Keyboard Mode Vulnerability in Systemd Affects Linux Users
CVE-2018-20839

4.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
17 May 2019

What is CVE-2018-20839?

A vulnerability in systemd version 242 allows attackers to potentially read cleartext passwords during logout due to improper handling of the KDGKBMODE check. This can occur in scenarios such as watching a shutdown sequence or using keyboard shortcuts (Ctrl-Alt-F1 and Ctrl-Alt-F2). This issue arises from mishandling of keyboard mode settings, which can expose sensitive information to unauthorized users.

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.