HomeSystemd ProjectCVE-2020-13776

CVE-2020-13776

MEDIUM
6.7CVSS
Published: 2020-06-03
Updated: 2025-06-09
AI Analysis

Description

systemd through v245 mishandles numerical usernames such as ones composed of decimal digits or 0x followed by hex digits, as demonstrated by use of root privileges when privileges of the 0x0 user account were intended. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000082.

CVSS Metrics

Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Attack Vector
local
Complexity
high
Privileges
low
User Action
required
Scope
unchanged
Confidentiality
high
Integrity
high
Availability
high
Weaknesses
CWE-269CWE-269

Metadata

Primary Vendor
SYSTEMD_PROJECT
Published
6/3/2020
Last Modified
6/9/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

systemd_project : systemdnetapp : active_iq_unified_managernetapp : solidfire_\&_hci_management_nodefedoraproject : fedora

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2020-13776 | MEDIUM Severity | CVEDatabase.com | CVEDatabase.com