CVE-2020-21583
published 2023-08-22CVE-2020-21583: An issue was discovered in hwclock.13-v2.27 allows attackers to gain escalated privlidges or execute arbitrary commands via the path parameter when setting the…
PriorityP433medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.52%
40.7th percentile
An issue was discovered in hwclock.13-v2.27 allows attackers to gain escalated privlidges or execute arbitrary commands via the path parameter when setting the date.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | util-linux | < util-linux 2.27-1 (bookworm) | util-linux 2.27-1 (bookworm) |
| kernel | util-linux | < 2.27 | 2.27 |
| kernel | util-linux | >= 0 < 2.27-1 | 2.27-1 |
| kernel | util-linux | >= 0 < 2.27-1 | 2.27-1 |
| kernel | util-linux | >= 0 < 2.27-1 | 2.27-1 |
| kernel | util-linux | >= 0 < 2.27-1 | 2.27-1 |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
osv6.7MEDIUM
vendor_debian6.7MEDIUM
vendor_redhat6.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
util-linux: arbitrary commands execution via the path parameter
vendor_redhat·2023-08-22·CVSS 6.7
CVE-2020-21583 [MEDIUM] CWE-78 util-linux: arbitrary commands execution via the path parameter
util-linux: arbitrary commands execution via the path parameter
An issue was discovered in hwclock.13-v2.27 allows attackers to gain escalated privlidges or execute arbitrary commands via the path parameter when setting the date.
A vulnerability was found in hwclock in util-linux, which allowed non-root users to access the hardware clock. This flaw allows an attacker to execute arbitrary code via the path parameter when setting the date.
Statement: This presents an issue only in scenarios where the administrator has configured hwclock to be setuid root. However, it's important to note that this is a non-default and unlikely configuration.
Package: util-linux (Red Hat Enterprise Linux 7) - Out of support scope
Package: util-linux (Red Hat Enterprise Linux 8) - Not affected
Package: ut
Debian
CVE-2020-21583: util-linux - An issue was discovered in hwclock.13-v2.27 allows attackers to gain escalated p...
vendor_debian·2020·CVSS 6.7
CVE-2020-21583 [MEDIUM] CVE-2020-21583: util-linux - An issue was discovered in hwclock.13-v2.27 allows attackers to gain escalated p...
An issue was discovered in hwclock.13-v2.27 allows attackers to gain escalated privlidges or execute arbitrary commands via the path parameter when setting the date.
Scope: local
bookworm: resolved (fixed in 2.27-1)
bullseye: resolved (fixed in 2.27-1)
forky: resolved (fixed in 2.27-1)
sid: resolved (fixed in 2.27-1)
trixie: resolved (fixed in 2.27-1)
OSV
CVE-2020-21583: An issue was discovered in hwclock
osv·2023-08-22·CVSS 6.7
CVE-2020-21583 [MEDIUM] CVE-2020-21583: An issue was discovered in hwclock
An issue was discovered in hwclock.13-v2.27 allows attackers to gain escalated privlidges or execute arbitrary commands via the path parameter when setting the date.
GHSA
GHSA-c5mr-x8m3-hpc9: An issue was discovered in hwclock
ghsa_unreviewed·2023-08-22
CVE-2020-21583 [MEDIUM] CWE-78 GHSA-c5mr-x8m3-hpc9: An issue was discovered in hwclock
An issue was discovered in hwclock.13-v2.27 allows attackers to gain escalated privlidges or execute arbitrary commands via the path parameter when setting the date.
No detection rules found.
No public exploits indexed.
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=786804https://packetstormsecurity.com/files/132061/hwclock-Privilege-Escalation.htmlhttps://bugs.debian.org/cgi-bin/bugreport.cgi?bug=786804https://packetstormsecurity.com/files/132061/hwclock-Privilege-Escalation.htmlhttps://security.netapp.com/advisory/ntap-20241220-0006/
2023-08-22
Published