CVE-2020-25654
CVE-2020-25654
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 2.0%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Lifecycle
24 Nov 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
An ACL bypass flaw was found in pacemaker. An attacker having a local account on the cluster and in the haclient group could use IPC communication with various daemons directly to perform certain tasks that they would be prevented by ACLs from doing if they went through the configuration.
Affected products
n/a · pacemakerWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →