CVE Vulnerabilities

CVE-2020-27780

Improper Authentication

Published: Dec 18, 2020 | Modified: Dec 28, 2020
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

A flaw was found in Linux-Pam in versions prior to 1.5.1 in the way it handle empty passwords for non-existing users. When the user doesnt exist PAM try to authenticate with root and in the case of an empty password it successfully authenticate.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Linux-pam Linux-pam 1.5.0 (including) 1.5.1 (excluding)

Potential Mitigations

References