7.2
CVSSv2

CVE-2014-0748

Published: 27/12/2014 Updated: 30/12/2014
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

apinit on Cray devices with CLE prior to 4.2.UP02 and 5.x prior to 5.1.UP00 does not use alpsauth data to validate the UID in a launch message, which allows local users to gain privileges via a modified aprun program, aka ID FN5912.

Vulnerable Product Search on Vulmon Subscribe to Product

cray cray linux environment

cray cray linux environment 5.1

Exploits

Apinit and aprun are utilities used to schedule tasks on Cray supercomputers Apinit runs as a service on compute nodes and aprun is used to communicate with these nodes The apinit service does not safely validate messages supplied to it through the use of aprun Users of Cray systems are able to exploit this weakness in order to execute commands ...