Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-43414

Опубликовано: 07 нояб. 2021
Источник: nvd
CVSS3: 7
CVSS2: 6.9
EPSS Низкий

Описание

An issue was discovered in GNU Hurd before 0.9 20210404-9. The use of an authentication protocol in the proc server is vulnerable to man-in-the-middle attacks, which can be exploited for local privilege escalation to get full root access.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:gnu:hurd:*:*:*:*:*:*:*:*
Версия до 0.9.20210404-9 (исключая)

EPSS

Процентиль: 8%
0.00028
Низкий

7 High

CVSS3

6.9 Medium

CVSS2

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 7
debian
больше 4 лет назад

An issue was discovered in GNU Hurd before 0.9 20210404-9. The use of ...

CVSS3: 7
github
больше 3 лет назад

An issue was discovered in GNU Hurd before 0.9 20210404-9. The use of an authentication protocol in the proc server is vulnerable to man-in-the-middle attacks, which can be exploited for local privilege escalation to get full root access.

EPSS

Процентиль: 8%
0.00028
Низкий

7 High

CVSS3

6.9 Medium

CVSS2

Дефекты

CWE-287