Authentication Flaw in Linux-Pam Affects User Security
CVE-2020-27780

9.8CRITICAL

Key Information:

Vendor

Linux-pam

Status
Vendor
CVE Published:
18 December 2020

What is CVE-2020-27780?

A vulnerability exists in Linux-Pam prior to version 1.5.1, where the handling of empty passwords for non-existing users leads to unauthorized authentication. When a user attempts to log in with an empty password, the system erroneously attempts to authenticate them as root, thereby bypassing standard security measures and potentially compromising system integrity.

Affected Version(s)

pam pam 1.5.1

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.