CYBER CODE RED

Get real-time updates on Telegram

P5Verified

CVE-2021-25317: cups before 1.3.9 (exclusive), before 2.2.7 (exclusive), before 1.7.5 (exclusive) (+1 more affected versions); +6 more…

CVE-2021-25317. CVSS 3.1 base score 3.3 (LOW, NVD). EPSS 0.00268 (percentile 0.17398), scored 2026-10-08.

Affected technology

cups · before 1.3.9 (exclusive)
suse

fedora · 32
fedoraproject

fedora · 33
fedoraproject

fedora · 34
fedoraproject

cups · before 2.2.7 (exclusive)
suse

cups · before 1.7.5 (exclusive)
suse

cups · through 2.3.3op2-2.1 (inclusive)
suse

SUSE Linux Enterprise Server 11-SP4-LTSS · cups to before 1.3.9
SUSE

SUSE Manager Server 4.0 · cups to before 2.2.7
SUSE

SUSE OpenStack Cloud Crowbar 9 · cups to before 1.7.5
SUSE

openSUSE Leap 15.2 · cups to before 2.2.7
openSUSE

Factory · cups through 2.3.3op2-2.1
openSUSE

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 3.1): Local · Low privileges required · No user interaction required

Attack conditions (NVD, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

Local attackers with control of the lp users can create files as root with 0644 permissions without the ability to set the content. Vendor/CNA’s CVSS 3.1 assessment (base score 3.3/10) rates confidentiality and availability impact as none; integrity impact as low. NVD’s CVSS 3.1 assessment (base score 3.3/10) rates confidentiality and availability impact as none; integrity impact as low.

Published

CWE
CWE-276
CCR priority
13.3 /100 (P5)
CVSS 3.1
3.3 /10 · CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N · NVD
EPSS
0.00268 · percentile 0.17398 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2021-25317.html