CVE-2021-25314
Published Apr 14, 2021
Last updated 2 years ago
Overview
- Description
- A Creation of Temporary File With Insecure Permissions vulnerability in hawk2 of SUSE Linux Enterprise High Availability 12-SP3, SUSE Linux Enterprise High Availability 12-SP5, SUSE Linux Enterprise High Availability 15-SP2 allows local attackers to escalate to root. This issue affects: SUSE Linux Enterprise High Availability 12-SP3 hawk2 versions prior to 2.6.3+git.1614685906.812c31e9. SUSE Linux Enterprise High Availability 12-SP5 hawk2 versions prior to 2.6.3+git.1614685906.812c31e9. SUSE Linux Enterprise High Availability 15-SP2 hawk2 versions prior to 2.6.3+git.1614684118.af555ad9.
- Source
- meissner@suse.de
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 7.8
- Impact score
- 5.9
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
CVSS 2.0
- Type
- Primary
- Base score
- 7.2
- Impact score
- 10
- Exploitability score
- 3.9
- Vector string
- AV:L/AC:L/Au:N/C:C/I:C/A:C
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:suse:linux_enterprise_high_availability_extension:12:sp3:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "AA8ACCE8-426F-4956-8E15-733E1317A3B3" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:suse:hawk2:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3C3980F5-90DD-463A-AE25-3FABC73AE7D8", "versionEndExcluding": "2.6.3\\+git.1614685906.812c31e9-2.42.1" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:suse:linux_enterprise_high_availability_extension:15:sp2:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "75369E9E-2A37-434F-8241-1514E0FD8F82" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:suse:hawk2:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C2832040-A0EB-47B0-A518-D51A75B1D88D", "versionEndExcluding": "2.6.3\\+git.1614684118.af555ad9" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:suse:linux_enterprise_high_availability_extension:12:sp5:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "09774141-B610-4DFD-8D09-5D64373C08F4" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:suse:hawk2:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B9B732E1-A352-4B3E-B4DF-28D7F981AEC8", "versionEndExcluding": "2.6.3\\+git.1614685906.812c31e9" } ], "operator": "OR" } ], "operator": "AND" } ]