CVE Vulnerabilities

CVE-2016-4484

Improper Authentication

Published: Jan 23, 2017 | Modified: Jan 26, 2017
CVSS 3.x
6.8
MEDIUM
Source:
NVD
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
7.2 MODERATE
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V3
6.8 MODERATE
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Ubuntu
LOW

The Debian initrd script for the cryptsetup package 2:1.7.3-2 and earlier allows physically proximate attackers to gain shell access via many log in attempts with an invalid password.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Cryptsetup Cryptsetup_project * 2.1.7.3-2 (including)
Cryptsetup Ubuntu artful *
Cryptsetup Ubuntu cosmic *
Cryptsetup Ubuntu disco *
Cryptsetup Ubuntu eoan *
Cryptsetup Ubuntu esm-infra-legacy/trusty *
Cryptsetup Ubuntu esm-infra/xenial *
Cryptsetup Ubuntu precise *
Cryptsetup Ubuntu precise/esm *
Cryptsetup Ubuntu trusty *
Cryptsetup Ubuntu trusty/esm *
Cryptsetup Ubuntu upstream *
Cryptsetup Ubuntu vivid/stable-phone-overlay *
Cryptsetup Ubuntu vivid/ubuntu-core *
Cryptsetup Ubuntu xenial *
Cryptsetup Ubuntu yakkety *
Cryptsetup Ubuntu zesty *

Potential Mitigations

References