Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-29800

Опубликовано: 21 сент. 2022
Источник: nvd
CVSS3: 4.7
EPSS Низкий

Описание

A time-of-check-time-of-use (TOCTOU) race condition vulnerability was found in networkd-dispatcher. This flaw exists because there is a certain time between the scripts being discovered and them being run. An attacker can abuse this vulnerability to replace scripts that networkd-dispatcher believes to be owned by root with ones that are not.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:microsoft:windows_defender_for_endpoint:-:*:*:*:*:linux:*:*

EPSS

Процентиль: 48%
0.00254
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-367
CWE-367

Связанные уязвимости

CVSS3: 4.7
ubuntu
больше 3 лет назад

A time-of-check-time-of-use (TOCTOU) race condition vulnerability was found in networkd-dispatcher. This flaw exists because there is a certain time between the scripts being discovered and them being run. An attacker can abuse this vulnerability to replace scripts that networkd-dispatcher believes to be owned by root with ones that are not.

CVSS3: 4.7
redhat
почти 4 года назад

A time-of-check-time-of-use (TOCTOU) race condition vulnerability was found in networkd-dispatcher. This flaw exists because there is a certain time between the scripts being discovered and them being run. An attacker can abuse this vulnerability to replace scripts that networkd-dispatcher believes to be owned by root with ones that are not.

CVSS3: 4.7
debian
больше 3 лет назад

A time-of-check-time-of-use (TOCTOU) race condition vulnerability was ...

CVSS3: 4.7
github
больше 3 лет назад

A time-of-check-time-of-use (TOCTOU) race condition vulnerability was found in networkd-dispatcher. This flaw exists because there is a certain time between the scripts being discovered and them being run. An attacker can abuse this vulnerability to replace scripts that networkd-dispatcher believes to be owned by root with ones that are not.

EPSS

Процентиль: 48%
0.00254
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-367
CWE-367