Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2025-11019

Опубликовано: 11 сент. 2025
Источник: fstec
CVSS3: 8.4
CVSS2: 7.2
EPSS Низкий

Описание

Уязвимость системы печати CUPS (Common UNIX Printing System) связана с недостатками процедуры аутентификации. Эксплуатация уязвимости может позволить нарушителю обойти существующие ограничения безопасности и получить несанкционированный доступ к системе путем отправки специально сформированного запроса

Вендор

Red Hat Inc.
Canonical Ltd.
Сообщество свободного программного обеспечения
ООО «РусБИТех-Астра»
АО «НТЦ ИТ РОСА»
Novell Inc.
Fedora Project
АО «НППКТ»
ООО «НЦПР»
ООО «Ред Софт»

Наименование ПО

Red Hat Enterprise Linux
Ubuntu
OpenShift Container Platform
Debian GNU/Linux
Astra Linux Special Edition
РОСА Кобальт
Astra Linux Common Edition
ROSA Virtualization
РОСА ХРОМ
SUSE Liberty Linux
Fedora
Suse Linux Enterprise Server
ROSA Virtualization 3.0
SUSE Linux Enterprise Server LTSS Extended Security
CUPS
ОСОН ОСнова Оnyx
МСВСфера
РЕД ОС
Red Hat Hardened Images
OpenShift Serverless

Версия ПО

6 (Red Hat Enterprise Linux)
7 (Red Hat Enterprise Linux)
16.04 LTS (Ubuntu)
18.04 LTS (Ubuntu)
8 (Red Hat Enterprise Linux)
4 (OpenShift Container Platform)
20.04 LTS (Ubuntu)
11 (Debian GNU/Linux)
12 (Debian GNU/Linux)
1.7 (Astra Linux Special Edition)
4.7 (Astra Linux Special Edition)
22.04 LTS (Ubuntu)
9 (Red Hat Enterprise Linux)
8.2 Advanced Update Support (Red Hat Enterprise Linux)
7.9 (РОСА Кобальт)
1.6 «Смоленск» (Astra Linux Common Edition)
2.1 (ROSA Virtualization)
12.4 (РОСА ХРОМ)
8.4 Advanced Mission Critical Update Support (Red Hat Enterprise Linux)
8 (SUSE Liberty Linux)
41 (Fedora)
24.04 LTS (Ubuntu)
4.12 (OpenShift Container Platform)
9.0 Update Services for SAP Solutions (Red Hat Enterprise Linux)
8.6 Update Services for SAP Solutions (Red Hat Enterprise Linux)
8.6 Telecommunications Update Service (Red Hat Enterprise Linux)
8.6 Advanced Mission Critical Update Support (Red Hat Enterprise Linux)
7 Extended Lifecycle Support (Red Hat Enterprise Linux)
12 SP5-LTSS (Suse Linux Enterprise Server)
24.10 (Ubuntu)
9.4 Extended Update Support (Red Hat Enterprise Linux)
3.0 (ROSA Virtualization 3.0)
12 SP5 (SUSE Linux Enterprise Server LTSS Extended Security)
42 (Fedora)
10 (Red Hat Enterprise Linux)
8.8 Telecommunications Update Service (Red Hat Enterprise Linux)
8.8 Update Services for SAP Solutions (Red Hat Enterprise Linux)
9.2 Update Services for SAP Solutions (Red Hat Enterprise Linux)
13 (Debian GNU/Linux)
8.4 Extended Update Support Long-Life Add-On (Red Hat Enterprise Linux)
до 2.4.13 (CUPS)
до 2.14 (ОСОН ОСнова Оnyx)
9.5 (МСВСфера)
8.0 (РЕД ОС)
до 3.1 (ОСОН ОСнова Оnyx)
- (Red Hat Hardened Images)
1.36-RHEL-8 (OpenShift Serverless)

Тип ПО

Операционная система
Прикладное ПО информационных систем
ПО виртуализации/ПО виртуального программно-аппаратного средства

Операционные системы и аппаратные платформы

Red Hat Inc. Red Hat Enterprise Linux 6
Red Hat Inc. Red Hat Enterprise Linux 7
Canonical Ltd. Ubuntu 16.04 LTS
Canonical Ltd. Ubuntu 18.04 LTS
Red Hat Inc. Red Hat Enterprise Linux 8
Canonical Ltd. Ubuntu 20.04 LTS
Сообщество свободного программного обеспечения Debian GNU/Linux 11
Сообщество свободного программного обеспечения Debian GNU/Linux 12
ООО «РусБИТех-Астра» Astra Linux Special Edition 1.7
ООО «РусБИТех-Астра» Astra Linux Special Edition 4.7
Canonical Ltd. Ubuntu 22.04 LTS
Red Hat Inc. Red Hat Enterprise Linux 9
Red Hat Inc. Red Hat Enterprise Linux 8.2 Advanced Update Support
АО «НТЦ ИТ РОСА» РОСА Кобальт 7.9
ООО «РусБИТех-Астра» Astra Linux Common Edition 1.6 «Смоленск»
АО «НТЦ ИТ РОСА» ROSA Virtualization 2.1
АО «НТЦ ИТ РОСА» РОСА ХРОМ 12.4
Red Hat Inc. Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
Novell Inc. SUSE Liberty Linux 8
Fedora Project Fedora 41
Canonical Ltd. Ubuntu 24.04 LTS
Red Hat Inc. Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
Red Hat Inc. Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
Red Hat Inc. Red Hat Enterprise Linux 8.6 Telecommunications Update Service
Red Hat Inc. Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
Red Hat Inc. Red Hat Enterprise Linux 7 Extended Lifecycle Support
Novell Inc. Suse Linux Enterprise Server 12 SP5-LTSS
Canonical Ltd. Ubuntu 24.10
Red Hat Inc. Red Hat Enterprise Linux 9.4 Extended Update Support
АО «НТЦ ИТ РОСА» ROSA Virtualization 3.0 3.0
Fedora Project Fedora 42
Red Hat Inc. Red Hat Enterprise Linux 10
Red Hat Inc. Red Hat Enterprise Linux 8.8 Telecommunications Update Service
Red Hat Inc. Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
Red Hat Inc. Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
Сообщество свободного программного обеспечения Debian GNU/Linux 13
Red Hat Inc. Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
Fedora Project Fedora 43
АО «НППКТ» ОСОН ОСнова Оnyx до 2.14
ООО «НЦПР» МСВСфера 9.5
ООО «Ред Софт» РЕД ОС 8.0
АО «НППКТ» ОСОН ОСнова Оnyx до 3.1

Уровень опасности уязвимости

Высокий уровень опасности (базовая оценка CVSS 2.0 составляет 7,2)
Высокий уровень опасности (базовая оценка CVSS 3.1 составляет 8,4)

Возможные меры по устранению уязвимости

Установка обновлений из доверенных источников. В связи со сложившейся обстановкой и введенными санкциями против Российской Федерации рекомендуется устанавливать обновления программного обеспечения только после оценки всех сопутствующих рисков.
Компенсирующие меры:
- настройка механизма аутентификации путем установления значения «Basic» для параметра «AuthType»;
- использование SIEM-систем для отслеживания событий, связанных с аутентификацией пользователя «admin».
Использование рекомендаций:
Для CUPS:
https://github.com/OpenPrinting/cups/commit/595d691075b1d396d2edfaa0a8fd0873a0a1f221
Для программных продуктов Red Hat Inc.:
https://access.redhat.com/security/cve/cve-2025-58060
Для программных продуктов Novell Inc.:
https://www.suse.com/security/cve/CVE-2025-58060.html
Для Fedora:
https://bodhi.fedoraproject.org/updates/FEDORA-2025-3596273b51
Обновление программного обеспечения cups до версии 2.4.10-4osnova2u1
Для программной системы управления средой виртуализации с подсистемой безагентного резервного копирования виртуальных машин «ROSA Virtualization 3.0»:
https://abf.rosa.ru/advisories/ROSA-SA-2025-3041
Для системы управления средой виртуализации «ROSA Virtualization»:
https://abf.rosa.ru/advisories/ROSA-SA-2025-3039
Для МСВСфера: https://errata.msvsphere-os.ru/definition/9/INFCSA-2025:15700?lang=ru
Для ОС Astra Linux:
обновить пакет cups до 2.3.3op2-4astra.se45 или более высокой версии, используя рекомендации производителя: https://wiki.astralinux.ru/astra-linux-se17-bulletin-2025-1202SE17
Для ОС Astra Linux:
обновить пакет cups до 2.3.3op2-4astra.se45 или более высокой версии, используя рекомендации производителя: https://wiki.astralinux.ru/astra-linux-se47-bulletin-2025-1216SE47
Для ОС Astra Linux:
обновить пакет cups до 2.2.13-1astra.se36 или более высокой версии, используя рекомендации производителя: https://wiki.astralinux.ru/astra-linux-se16-bulletin-20251225SE16
Для ОСОН ОСнова Оnyx: Обновление программного обеспечения cups до версии 2.4.16-1osnova3u1
Для ОС РОСА "КОБАЛЬТ": https://abf.rosa.ru/advisories/ROSA-SA-2025-3081
Для операционной системы РОСА ХРОМ: https://abf.rosa.ru/advisories/ROSA-SA-2026-3124
Для Ред ОС:
http://repo.red-soft.ru/redos/8.0/x86_64/updates/
Для Debian GNU/Linux:
https://security-tracker.debian.org/tracker/CVE-2025-58060
Для Ubuntu:
https://ubuntu.com/security/CVE-2025-58060

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Существует в открытом доступе

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 57%
0.00964
Низкий

8.4 High

CVSS3

7.2 High

CVSS2

Связанные уязвимости

CVSS3: 8.4
redos
около 1 месяца назад

Уязвимость cups

CVSS3: 8
ubuntu
11 месяцев назад

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.12 and earlier, when the `AuthType` is set to anything but `Basic`, if the request contains an `Authorization: Basic ...` header, the password is not checked. This results in authentication bypass. Any configuration that allows an `AuthType` that is not `Basic` is affected. Version 2.4.13 fixes the issue.

CVSS3: 8
redhat
11 месяцев назад

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.12 and earlier, when the `AuthType` is set to anything but `Basic`, if the request contains an `Authorization: Basic ...` header, the password is not checked. This results in authentication bypass. Any configuration that allows an `AuthType` that is not `Basic` is affected. Version 2.4.13 fixes the issue.

CVSS3: 8
nvd
11 месяцев назад

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.12 and earlier, when the `AuthType` is set to anything but `Basic`, if the request contains an `Authorization: Basic ...` header, the password is not checked. This results in authentication bypass. Any configuration that allows an `AuthType` that is not `Basic` is affected. Version 2.4.13 fixes the issue.

CVSS3: 8
msrc
11 месяцев назад

cups has Authentication bypass with AuthType Negotiate

EPSS

Процентиль: 57%
0.00964
Низкий

8.4 High

CVSS3

7.2 High

CVSS2