MEDIUM · 6.7

CVE-2020-13776

systemd through v245 mishandles numerical usernames such as ones composed of decimal digits or 0x followed by hex digits, as demonstrated by use of root privileges when privileges of the 0x0 user acco...

Vulnerability Description

systemd through v245 mishandles numerical usernames such as ones composed of decimal digits or 0x followed by hex digits, as demonstrated by use of root privileges when privileges of the 0x0 user account were intended. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000082.

CVSS Score

6.7

MEDIUM

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
Systemd ProjectSystemd<= 245
NetappActive Iq Unified Manager-
NetappSolidfire \& Hci Management Node-
FedoraprojectFedora32

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-13776?

CVE-2020-13776 is a vulnerability with a CVSS score of 6.7 (MEDIUM). systemd through v245 mishandles numerical usernames such as ones composed of decimal digits or 0x followed by hex digits, as demonstrated by use of root privileges when privileges of the 0x0 user acco...

How severe is CVE-2020-13776?

CVE-2020-13776 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-13776?

Check the references section above for vendor advisories and patch information. Affected products include: Systemd Project Systemd, Netapp Active Iq Unified Manager, Netapp Solidfire \& Hci Management Node, Fedoraproject Fedora.