7.2
CVSSv2

CVE-2014-5220

Published: 08/06/2018 Updated: 07/11/2023
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The mdcheck script of the mdadm package for openSUSE 13.2 prior to version 3.3.1-5.14.1 does not properly sanitize device names, which allows local malicious users to execute arbitrary commands as root.

Vulnerable Product Search on Vulmon Subscribe to Product

opensuse opensuse 13.2

mdadm project mdadm