Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-27780

Опубликовано: 18 дек. 2020
Источник: ubuntu
Приоритет: high
EPSS Низкий
CVSS2: 10
CVSS3: 9.8

Описание

A flaw was found in Linux-Pam in versions prior to 1.5.1 in the way it handle empty passwords for non-existing users. When the user doesn't exist PAM try to authenticate with root and in the case of an empty password it successfully authenticate.

РелизСтатусПримечание
bionic

not-affected

devel

not-affected

esm-infra-legacy/trusty

not-affected

esm-infra-legacy/xenial

not-affected

esm-infra/bionic

not-affected

esm-infra/focal

not-affected

esm-infra/xenial

not-affected

focal

not-affected

groovy

not-affected

precise/esm

not-affected

Показывать по

EPSS

Процентиль: 78%
0.01959
Низкий

10 Critical

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 8.1
redhat
почти 6 лет назад

A flaw was found in Linux-Pam in versions prior to 1.5.1 in the way it handle empty passwords for non-existing users. When the user doesn't exist PAM try to authenticate with root and in the case of an empty password it successfully authenticate.

CVSS3: 9.8
nvd
больше 5 лет назад

A flaw was found in Linux-Pam in versions prior to 1.5.1 in the way it handle empty passwords for non-existing users. When the user doesn't exist PAM try to authenticate with root and in the case of an empty password it successfully authenticate.

CVSS3: 9.8
msrc
больше 5 лет назад

A flaw was found in Linux-Pam in versions prior to 1.5.1 in the way it handle empty passwords for non-existing users. When the user doesn't exist PAM try to authenticate with root and in the case of an empty password it successfully authenticate.

CVSS3: 9.8
debian
больше 5 лет назад

A flaw was found in Linux-Pam in versions prior to 1.5.1 in the way it ...

github
около 4 лет назад

A flaw was found in Linux-Pam in versions prior to 1.5.1 in the way it handle empty passwords for non-existing users. When the user doesn't exist PAM try to authenticate with root and in the case of an empty password it successfully authenticate.

EPSS

Процентиль: 78%
0.01959
Низкий

10 Critical

CVSS2

9.8 Critical

CVSS3