CVE-2021-33393

EUVD-2021-20099
lfs/backup in IPFire 2.25-core155 does not ensure that /var/ipfire/backup/bin/backup.pl is owned by the root account. It might be owned by an unprivileged account, which could potentially be used to install a Trojan horse backup.pl script that is later executed by root. Similar problems with the ownership/permissions of other files may be present as well.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 98%
Affected Products (NVD)
VendorProductVersion
ipfireipfire
𝑥
< 2.25
ipfireipfire
2.25:core_update141
ipfireipfire
2.25:core_update142
ipfireipfire
2.25:core_update143
ipfireipfire
2.25:core_update144
ipfireipfire
2.25:core_update145
ipfireipfire
2.25:core_update146
ipfireipfire
2.25:core_update147
ipfireipfire
2.25:core_update148
ipfireipfire
2.25:core_update149
ipfireipfire
2.25:core_update150
ipfireipfire
2.25:core_update151
ipfireipfire
2.25:core_update152
ipfireipfire
2.25:core_update155
ipfireipfire
2.25:core_update156
𝑥
= Vulnerable software versions