VDB

CVE-2021-25314

CVE-2021-25314 PUBLISHED CVSS 7.800000190734863 HIGH

A Creation of Temporary File With Insecure Permissions vulnerability in hawk2 of SUSE Linux Enterprise High Availability 12-SP3, SUSE Linux Enterprise High Availability 12-SP5, SUSE Linux Enterprise High Availability 15-SP2 allows local attackers to escalate to root. This issue affects: SUSE Linux Enterprise High Availability 12-SP3 hawk2 versions prior to 2.6.3+git.1614685906.812c31e9. SUSE Linux Enterprise High Availability 12-SP5 hawk2 versions prior to 2.6.3+git.1614685906.812c31e9. SUSE Linux Enterprise High Availability 15-SP2 hawk2 versions prior to 2.6.3+git.1614684118.af555ad9.

EPSS 0.03% · 8.6th percentile

Risk Scores

CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.03%
8.6th percentile

Affected Products

VendorProductVersions
SUSESUSE Linux Enterprise High Availability 15-SP2hawk2
SUSESUSE Linux Enterprise High Availability 12-SP5hawk2
SUSESUSE Linux Enterprise High Availability 12-SP3hawk2
susehawk20, 0, 0

Exploit Intelligence

Timeline

  • Mar 25, 2021 CVE Published
  • Apr 15, 2021 EPSS Score
  • Jun 24, 2021 EPSS Score
  • Aug 25, 2021 EPSS Score
  • Dec 28, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Mar 1, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 2, 2022 EPSS Score
  • Jul 4, 2022 EPSS Score
  • Nov 7, 2022 EPSS Score
  • Dec 29, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›