cbcvebase.
CVE-2016-4484
published 2017-01-23

CVE-2016-4484: The Debian initrd script for the cryptsetup package 2:1.7.3-2 and earlier allows physically proximate attackers to gain shell access via many log in attempts…

PriorityP429medium6.8CVSS 3.0
AVPACLPRNUINSUCHIHAH
EPSS
0.71%
49.8th percentile
The Debian initrd script for the cryptsetup package 2:1.7.3-2 and earlier allows physically proximate attackers to gain shell access via many log in attempts with an invalid password.

Affected

6 ranges
VendorProductVersion rangeFixed in
cryptsetup_projectcryptsetup<= 2.1.7.3-2
cryptsetup_projectcryptsetup>= 0 < 2:1.7.3-22:1.7.3-2
cryptsetup_projectcryptsetup>= 0 < 2:1.7.3-22:1.7.3-2
cryptsetup_projectcryptsetup>= 0 < 2:1.7.3-22:1.7.3-2
cryptsetup_projectcryptsetup>= 0 < 2:1.7.3-22:1.7.3-2
debiancryptsetup< cryptsetup 2:1.7.3-2 (bookworm)cryptsetup 2:1.7.3-2 (bookworm)

CVSS provenance

nvdv3.06.8MEDIUMCVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv6.8MEDIUM
vendor_debian6.8LOW
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.