CVE-2019-13033
18.06.2020, 18:15
In CISOfy Lynis 2.x through 2.7.5, the license key can be obtained by looking at the process list when a data upload is being performed. This license can be used to upload data to a central Lynis server. Although no data can be extracted by knowing the license key, it may be possible to upload the data of additional scans.Enginsight
| Vendor | Product | Version |
|---|---|---|
| cisofy | lynis | 2.0.0 ≤ 𝑥 ≤ 2.7.5 |
| debian | debian_linux | 8.0 |
| debian | debian_linux | 9.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References