VulnerabilityModified
CVE-2020-7209
LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2.
CRITICAL 9.8EPSS 98.8%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 98.8%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 98.75% probability · 100th percentile
- CISA KEV
- Not listed
- Affected
- hp/linuxki
- Source
- security-alert@hpe.com
References
- http://packetstormsecurity.com/files/157739/HP-LinuxKI-6.01-Remote-Command-Injection.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/158025/LinuxKI-Toolset-6.01-Remote-Command-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://github.com/HewlettPackard/LinuxKI/releases/tag/v6.0-2Third Party Advisory
- http://packetstormsecurity.com/files/157739/HP-LinuxKI-6.01-Remote-Command-Injection.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/158025/LinuxKI-Toolset-6.01-Remote-Command-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://github.com/HewlettPackard/LinuxKI/releases/tag/v6.0-2Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.