← Back

CVE-2021-25321

nvd nist
Published: Jun 30, 2021Modified: Jun 17, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

A UNIX Symbolic Link (Symlink) Following vulnerability in arpwatch of SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Manager Server 4.0, SUSE OpenStack Cloud Crowbar 9; openSUSE Factory, Leap 15.2 allows local attackers with control of the runtime user to run arpwatch as to escalate to root upon the next restart of arpwatch. This issue affects: SUSE Linux Enterprise Server 11-SP4-LTSS arpwatch versions prior to 2.1a15. SUSE Manager Server 4.0 arpwatch versions prior to 2.1a15. SUSE OpenStack Cloud Crowbar 9 arpwatch versions prior to 2.1a15. openSUSE Factory arpwatch version 2.1a15-169.5 and prior versions. openSUSE Leap 15.2 arpwatch version 2.1a15-lp152.5.5 and prior versions.

Affected (3)

Products: Suse: Arpwatch
1 product
Arpwatch
Configuration A
1 vulnerable · 3 platform
Vulnerable SoftwareAffected Versions
Before 2.1a15
Running on/withPlatform Versions
Suse
Linux Enterprise Server
Version 11 sp4
Suse
Manager Server
Version 4.0
Suse
Openstack Cloud Crowbar
Version 9.0
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 2.1a15-169.5
Running on/withPlatform Versions
Opensuse
Factory
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 2.1a15-lp152.5.5
Running on/withPlatform Versions
Opensuse
Leap
Version 15.2

References (2)

Source: meissner@suse.de
ExploitIssue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingVendor Advisory

Timeline

No history available yet.