CVE-2013-2069
Published May 29, 2013
Last updated 6 years ago
Overview
- Description
- Red Hat livecd-tools before 13.4.4, 17.x before 17.17, 18.x before 18.16, and 19.x before 19.3, when a rootpw directive is not set in a Kickstart file, sets the root user password to empty, which allows local users to gain privileges.
- Source
- secalert@redhat.com
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.2
- Impact score
- 10
- Exploitability score
- 3.9
- Vector string
- AV:L/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- CWE-264
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:redhat:livecd-tools:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9D42EA10-B72C-47D2-9901-3CD548560412", "versionEndExcluding": "13.4.4" }, { "criteria": "cpe:2.3:a:redhat:livecd-tools:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8ECF4AA2-8F29-4875-ADF0-643F96191333", "versionEndExcluding": "17.17", "versionStartIncluding": "17.0" }, { "criteria": "cpe:2.3:a:redhat:livecd-tools:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "43EE8BA3-8F11-4456-B0F7-0EAF05469EF4", "versionEndExcluding": "18.16", "versionStartIncluding": "18.0" }, { "criteria": "cpe:2.3:a:redhat:livecd-tools:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9788C94D-3246-4A4E-90A9-B22B72E62A6B", "versionEndExcluding": "19.3", "versionStartIncluding": "19.0" } ], "operator": "OR" } ] } ]