SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2008-5103

(exclamation point) and allows attackers to bypass intended login restrictions.

HIGH 7.2EPSS 0.47%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.47%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

The (1) python-vm-builder and (2) ubuntu-vm-builder implementations in VMBuilder 0.9 in Ubuntu 8.10 omit the -e option when invoking chpasswd with a root:! argument, which configures the root account with a cleartext password of ! (exclamation point) and allows attackers to bypass intended login restrictions.

CVSS 2.0
7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
EPSS
0.47% probability · 39th percentile
CISA KEV
Not listed
Weakness
CWE-255
Affected
dcgrendel/vmbuilder
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.