7
CVSSv3

CVE-2020-14342

Published: 09/09/2020 Updated: 07/11/2023
CVSS v2 Base Score: 4.4 | Impact Score: 6.4 | Exploitability Score: 3.4
CVSS v3 Base Score: 7 | Impact Score: 5.9 | Exploitability Score: 1
VMScore: 392
Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

It exists that cifs-utils incorrectly handled certain command-line arguments. A local attacker could possibly use this issue to obtain root privileges. (CVE-2022-27239)

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

samba cifs-utils

fedoraproject fedora 32

fedoraproject fedora 33

opensuse leap 15.1

Vendor Advisories

Debian Bug report logs - #970172 cifs-utils: CVE-2020-14342: Shell command injection vulnerability in mountcifs Package: src:cifs-utils; Maintainer for src:cifs-utils is Debian Samba Maintainers <pkg-samba-maint@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 12 Sep 2020 13: ...
Several security issues were fixed in cifs-utils ...