Vulnerability Description
An issue was discovered in Pi-Hole through 5.0. The local www-data user has sudo privileges to execute the pihole core script as root without a password, which could allow an attacker to obtain root access via shell metacharacters to this script's setdns command.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pi-Hole | Pi-Hole | < 5.1 |
Related Weaknesses (CWE)
References
- https://0xpanic.github.io/2020/07/21/Pihole.htmlExploitThird Party Advisory
- https://docs.pi-hole.net/core/pihole-command/Vendor Advisory
- https://0xpanic.github.io/2020/07/21/Pihole.htmlExploitThird Party Advisory
- https://docs.pi-hole.net/core/pihole-command/Vendor Advisory
FAQ
What is CVE-2020-14162?
CVE-2020-14162 is a vulnerability with a CVSS score of 7.8 (HIGH). An issue was discovered in Pi-Hole through 5.0. The local www-data user has sudo privileges to execute the pihole core script as root without a password, which could allow an attacker to obtain root a...
How severe is CVE-2020-14162?
CVE-2020-14162 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-14162?
Check the references section above for vendor advisories and patch information. Affected products include: Pi-Hole Pi-Hole.