Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2011-4578

17
FAUCET Score

CVE-2011-4578 describes a vulnerability in acpid (aka acpid2) before version 2.0.11, specifically within the event.c component. The flaw stems from an inappropriate umask setting during the execution of event-handler scripts, affecting tedfelix acpid2. This allows local users to potentially perform unauthorized write operations in script-created directories or read files generated by scripts through standard filesystem calls. The vulnerability has a CVSS score of 4.6 (AV:L/AC:L/Au:N/C:P/I:P/A:P), indicating a low severity. It requires local access and low attack complexity, with potential impacts on confidentiality, integrity, and availability. The EPSS score is very low at 0.00078, and its FAUCET Risk Score is 13/100. There is no evidence of active exploitation, and no exploit code is available in Metasploit, Nuclei, or ExploitDB. The CVE is not listed in the KEV catalog and has received no community discussion or media coverage, suggesting a lack of widespread attention or exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
<= 2.0.10CPE matchmatch criteria
cpe:2.3:a:tedfelix:acpid2:*:*:*:*:*:*:*:*
2.0.0CPE matchmatch criteria
cpe:2.3:a:tedfelix:acpid2:2.0.0:*:*:*:*:*:*:*
2.0.1CPE matchmatch criteria
cpe:2.3:a:tedfelix:acpid2:2.0.1:*:*:*:*:*:*:*
2.0.2CPE matchmatch criteria
cpe:2.3:a:tedfelix:acpid2:2.0.2:*:*:*:*:*:*:*
2.0.3CPE matchmatch criteria
cpe:2.3:a:tedfelix:acpid2:2.0.3:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

4.6MEDIUM

AV:L/AC:L/Au:N/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
LOCAL
Access Complexity
LOW
Authentication
NONE
Exploitability Score
3.9
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
0.39%
Probability of exploitation in next 30 days
EPSS Percentile
32.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0039 is in the 58th percentile among its peer group of 3,049 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (3)

redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: acpid
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: acpid
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: acpid

Vendor Advisories (1)

redhatCVE-2011-4578Low

acpid: Unsafe umask for actions executed by acpid

Jul 30, 2011

References

bugs.launchpad.net / ubuntu/+source/acpid/+bug/893821
bugzilla.redhat.com / show_bug.cgi
sourceforge.net / u/tedfelix/acpid2/ci/02d0bf29207f17996936ab652717855b15873901/tree/Changelog
mandriva.com / security/advisories
openwall.com / lists/oss-security/2011/12/06/3