SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-3784

Garuda Linux performs an insecure user creation and authentication that allows any user to impersonate the created account.

HIGH 7.0EPSS 0.16%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.16%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Garuda Linux performs an insecure user creation and authentication that allows any user to impersonate the created account. By creating users from the 'Garuda settings manager', an insecure procedure is performed that keeps the created user without an assigned password during some seconds. This could allow a potential attacker to exploit this vulnerability in order to authenticate without knowing the password.

CVSS 3.1
7.0 HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
0.16% probability · 5th percentile
CISA KEV
Not listed
Weakness
CWE-287
Affected
garudalinux/garuda linux
Source
cve-coordination@incibe.es

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.