CVE Vulnerabilities

CVE-2013-2069

Published: May 29, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
7.2 IMPORTANT
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Red Hat livecd-tools before 13.4.4, 17.x before 17.17, 18.x before 18.16, and 19.x before 19.3, when a rootpw directive is not set in a Kickstart file, sets the root user password to empty, which allows local users to gain privileges.

Affected Software

NameVendorStart VersionEnd Version
Livecd-toolsRedhat*13.4.4 (excluding)
Livecd-toolsRedhat17.0 (including)17.17 (excluding)
Livecd-toolsRedhat18.0 (including)18.16 (excluding)
Livecd-toolsRedhat19.0 (including)19.3 (excluding)
Red Hat Enterprise Linux Server (v. 6)RedHat*

References