CVE-2009-2084 describes a privilege escalation vulnerability in Simple Linux Utility for Resource Management (SLURM) versions 1.2 and 1.3 prior to 1.3.14. The flaw stems from improper supplementary group settings when the slurmd or slurmctld daemons invoke sbcast or strigger, potentially allowing local SLURM users to modify files and gain elevated privileges. With a CVSS score of 7.2, this vulnerability is rated as high severity. It has a local attack vector and low attack complexity, meaning an attacker would need local access to the system and the exploit would be relatively easy to execute. The potential impact includes complete compromise of confidentiality, integrity, and availability. There is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. The vulnerability has received minimal community attention, with no social media discussion or media coverage reported.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.3.13CPE matchmatch criteria | cpe:2.3:a:llnl:slurm:*:*:*:*:*:*:*:* | ||
1.2CPE matchmatch criteria | cpe:2.3:a:llnl:slurm:1.2:*:*:*:*:*:*:* | ||
1.3CPE matchmatch criteria | cpe:2.3:a:llnl:slurm:1.3:*:*:*:*:*:*:* | ||
1.3.1CPE matchmatch criteria | cpe:2.3:a:llnl:slurm:1.3.1:*:*:*:*:*:*:* | ||
1.3.2CPE matchmatch criteria | cpe:2.3:a:llnl:slurm:1.3.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.