The Debian initrd script for the cryptsetup package 2:1.7.3-2 and earlier allows physically proximate attackers to gain shell access via many log in attempts with an invalid password.
2017-01-23T21:59:01.533
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 6.8 (MEDIUM)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | cryptsetup_project | cryptsetup | ≤ 2.1.7.3-2 | Yes |