CVE-2021-25317Low· 3.3▾ SunlitA Incorrect Default Permissions vulnerability in the packaging of cups of SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Manager Server 4.0, SUSE OpenStack Cloud Crowbar 9; openSUSE Leap 15.2, Factory allows local attackers with control …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 18.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
A Incorrect Default Permissions vulnerability in the packaging of cups of SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Manager Server 4.0, SUSE OpenStack Cloud Crowbar 9; openSUSE Leap 15.2, Factory allows local attackers with control of the lp users to create files as root with 0644 permissions without the ability to set the content. This issue affects: SUSE Linux Enterprise Server 11-SP4-LTSS cups versions prior to 1.3.9. SUSE Manager Server 4.0 cups versions prior to 2.2.7. SUSE OpenStack Cloud Crowbar 9 cups versions prior to 1.7.5. openSUSE Leap 15.2 cups versions prior to 2.2.7. openSUSE Factory cups version 2.3.3op2-2.1 and prior versions.
cups < 1.3.9fedora = 32fedora = 33fedora = 34cups < 2.2.7cups < 1.7.5cups <= 2.3.3op2-2.1Upgrade past the affected range:
cups 2.2.7Connected by shared product, vendor, weakness, or advisory.
CVE-2025-61915Medium· 6.0OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems
CVE-2025-58436Medium· 5.1OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems
CVE-2026-27447Medium· 4.8OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems
CVE-2026-34978Medium· 6.5OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems
CVE-2023-20178High· 7.8A vulnerability in the client update process of Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Windows could allow a low-privileged, authenticated, local attacker to elevate privileges t…
CVE-2020-8022High· 7.7A Incorrect Default Permissions vulnerability in the packaging of tomcat on SUSE Enterprise Storage 5, SUSE Linux Enterprise Server 12-SP2-BCL, SUSE Linux Enterprise Server 12-SP2-LTSS, SUSE Linux Enterprise Server 12-SP3-BCL, SUSE Linux…