cbcvebase.
CVE-2014-9645
published 2017-03-12

CVE-2014-9645: The add_probe function in modutils/modprobe.c in BusyBox before 1.23.0 allows local users to bypass intended restrictions on loading kernel modules via a /…

PriorityP423medium5.5CVSS 3.0
AVLACLPRLUINSUCNIHAN
EPSS
0.64%
46.4th percentile
The add_probe function in modutils/modprobe.c in BusyBox before 1.23.0 allows local users to bypass intended restrictions on loading kernel modules via a / (slash) character in a module name, as demonstrated by an "ifconfig /usbserial up" command or a "mount -t /snd_pcm none /" command.

Affected

9 ranges
VendorProductVersion rangeFixed in
busyboxbusybox<= 1.22.1
busyboxbusybox>= 0 < 1:1.22.0-151:1.22.0-15
busyboxbusybox>= 0 < 1:1.22.0-151:1.22.0-15
busyboxbusybox>= 0 < 1:1.22.0-151:1.22.0-15
busyboxbusybox>= 0 < 1:1.22.0-151:1.22.0-15
busyboxbusybox>= 0 < 1:1.21.0-1ubuntu1.41:1.21.0-1ubuntu1.4
busyboxbusybox>= 0 < 1:1.22.0-15ubuntu1.41:1.22.0-15ubuntu1.4
busyboxbusybox>= 0 < 1:1.27.2-2ubuntu3.21:1.27.2-2ubuntu3.2
debianbusybox< busybox 1:1.22.0-15 (bookworm)busybox 1:1.22.0-15 (bookworm)

CVSS provenance

nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.