Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-28407

Опубликовано: 03 нояб. 2023
Источник: nvd
CVSS3: 7.1
EPSS Низкий

Описание

In swtpm before 0.4.2 and 0.5.x before 0.5.1, a local attacker may be able to overwrite arbitrary files via a symlink attack against a temporary file such as TMP2-00.permall.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:swtpm_project:swtpm:*:*:*:*:*:*:*:*
Версия до 0.4.2 (исключая)
cpe:2.3:a:swtpm_project:swtpm:0.5.0:*:*:*:*:*:*:*

EPSS

Процентиль: 3%
0.00015
Низкий

7.1 High

CVSS3

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 7.1
ubuntu
больше 2 лет назад

In swtpm before 0.4.2 and 0.5.x before 0.5.1, a local attacker may be able to overwrite arbitrary files via a symlink attack against a temporary file such as TMP2-00.permall.

CVSS3: 7.3
redhat
около 5 лет назад

In swtpm before 0.4.2 and 0.5.x before 0.5.1, a local attacker may be able to overwrite arbitrary files via a symlink attack against a temporary file such as TMP2-00.permall.

CVSS3: 7.1
debian
больше 2 лет назад

In swtpm before 0.4.2 and 0.5.x before 0.5.1, a local attacker may be ...

CVSS3: 7.1
github
больше 2 лет назад

In swtpm before 0.4.2 and 0.5.x before 0.5.1, a local attacker may be able to overwrite arbitrary files via a symlink attack against a temporary file such as TMP2-00.permall.

EPSS

Процентиль: 3%
0.00015
Низкий

7.1 High

CVSS3

Дефекты

CWE-59