Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-13776


systemd through v245 mishandles numerical usernames such as ones composed of decimal digits or 0x followed by hex digits, as demonstrated by use of root privileges when privileges of the 0x0 user account were intended. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000082.


Published

2020-06-03T03:15:10.677

Last Modified

2025-06-09T16:15:31.573

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.7 (MEDIUM)

CVSSv2 Vector

AV:L/AC:H/Au:N/C:C/I:C/A:C

  • Access Vector: LOCAL
  • Access Complexity: HIGH
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

1.9

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-269
  • Type: Secondary
    CWE-269

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application systemd_project systemd ≤ 245 Yes
Application netapp active_iq_unified_manager - Yes
Application netapp solidfire_\&_hci_management_node - Yes
Operating System fedoraproject fedora 32 Yes

References