CVE-2016-4484
Cryptsetup 2:1.7.3-2 Root Initramfs Shell
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The Debian initrd script for the cryptsetup package 2:1.7.3-2 and earlier allows physically proximate attackers to gain shell access via many log in attempts with an invalid password.
La secuencia de comandos initrd de Debian para el paquete cryptsetup 2:1.7.3-2 y versiones anteriores permite a atacantes físicamente próximos obtener acceso a shell a través de muchos intentos de inicio de sesión con una contraseña no válida.
A vulnerability in Cryptsetup, concretely in the scripts that unlock the system partition when the partition is ciphered using LUKS (Linux Unified Key Setup). This vulnerability allows to obtain a root initramfs shell on affected systems. The vulnerability is very reliable because it doesn't depend on specific systems or configurations. Attackers can copy, modify or destroy the hard disc as well as set up the network to data. In cloud environments it is also possible to remotely exploit this vulnerability without having "physical access". Cryptsetup versions 2:1.7.3-2 and below are affected.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-05-04 CVE Reserved
- 2016-11-16 CVE Published
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- 2025-07-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-287: Improper Authentication
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://www.openwall.com/lists/oss-security/2016/11/14/13 | Mailing List |
|
http://www.openwall.com/lists/oss-security/2016/11/15/1 | Mailing List |
|
http://www.openwall.com/lists/oss-security/2016/11/15/4 | Mailing List |
|
http://www.openwall.com/lists/oss-security/2016/11/16/6 | Mailing List |
|
http://www.securityfocus.com/bid/94315 | Vdb Entry |
URL | Date | SRC |
---|---|---|
http://hmarco.org/bugs/CVE-2016-4484/CVE-2016-4484_cryptsetup_initrd_shell.html | 2024-08-06 |
URL | Date | SRC |
---|---|---|
https://gitlab.com/cryptsetup/cryptsetup/commit/ef8a7d82d8d3716ae9b58179590f7908981fa0cb | 2017-01-26 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cryptsetup Project Search vendor "Cryptsetup Project" | Cryptsetup Search vendor "Cryptsetup Project" for product "Cryptsetup" | <= 2.1.7.3-2 Search vendor "Cryptsetup Project" for product "Cryptsetup" and version " <= 2.1.7.3-2" | - |
Affected
|