7.8
CVE-2019-5164
- EPSS 0.73%
- Veröffentlicht 03.12.2019 22:15:15
- Zuletzt bearbeitet 21.11.2024 04:44:28
- Erkennungen
An exploitable code execution vulnerability exists in the ss-manager binary of Shadowsocks-libev 3.3.2. Specially crafted network packets sent to ss-manager can cause an arbitrary binary to run, resulting in code execution and privilege escalation. An attacker can send network packets to trigger this vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Shadowsocks ≫ Shadowsocks-libev Version 3.3.2
Opensuse ≫ Backports Sle Version 15.0 Update sp1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.73% | 0.495 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 4.6 | 3.9 | 6.4 |
AV:L/AC:L/Au:N/C:P/I:P/A:P
|
| Cisco Talos | 7.8 | 1.8 | 5.9 |
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-306 Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00023.html
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00061.html
https://talosintelligence.com/vulnerability_reports/TALOS-2019-0958