Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-29906

Опубликовано: 29 апр. 2025
Источник: nvd
CVSS3: 8.6
EPSS Низкий

Описание

Finit is a fast init for Linux systems. Versions starting from 3.0-rc1 and prior to version 4.11 bundle an implementation of getty for the tty configuration directive that can bypass /bin/login, i.e., a user can log in as any user without authentication. This issue has been patched in version 4.11.

EPSS

Процентиль: 5%
0.00021
Низкий

8.6 High

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 8.6
ubuntu
9 месяцев назад

Finit is a fast init for Linux systems. Versions starting from 3.0-rc1 and prior to version 4.11 bundle an implementation of getty for the `tty` configuration directive that can bypass `/bin/login`, i.e., a user can log in as any user without authentication. This issue has been patched in version 4.11.

CVSS3: 8.6
debian
9 месяцев назад

Finit is a fast init for Linux systems. Versions starting from 3.0-rc1 ...

CVSS3: 8.6
fstec
11 месяцев назад

Уязвимость компонента getty системы инициализации finit, позволяющая нарушителю получить несанкционированный доступ к системе

EPSS

Процентиль: 5%
0.00021
Низкий

8.6 High

CVSS3

Дефекты

CWE-287