CVE-2016-4484
MEDIUMCryptsetup < 2.1.7.3-2 - Authentication Bypass
Title source: ruleDescription
The Debian initrd script for the cryptsetup package 2:1.7.3-2 and earlier allows physically proximate attackers to gain shell access via many log in attempts with an invalid password.
References (7)
Scores
CVSS v3
6.8
EPSS
0.0046
EPSS Percentile
63.7%
Attack Vector
PHYSICAL
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-287
Status
draft
Affected Products (1)
cryptsetup_project/cryptsetup
< 2.1.7.3-2
Timeline
Published
Jan 23, 2017
Tracked Since
Feb 18, 2026