Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2013-4342

22
FAUCET Score

CVE-2013-4342 describes a privilege escalation vulnerability in xinetd, affecting Red Hat Enterprise Linux and xinetd itself. The flaw stems from xinetd failing to enforce user and group configurations for TCPMUX services, leading to these services running as root. This significantly increases the risk of remote attackers gaining root privileges if another vulnerability exists within a TCPMUX service. With a CVSS score of 7.6, this vulnerability is rated as high severity due to its network-based attack vector and complete compromise of confidentiality, integrity, and availability, despite requiring high attack complexity. The EPSS score of 0.15271 indicates a moderate likelihood of exploitation. Currently, there is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting a low level of public attention.

Impacted Technologies

VendorProductVersion(s)CPE
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:xinetd:xinetd:-:*:*:*:*:*:*:*
5CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux:5:*:*:*:*:*:*:*
6.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

7.6HIGH

AV:N/AC:H/Au:N/C:C/I:C/A:C

Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
Access Vector
NETWORK
Access Complexity
HIGH
Authentication
NONE
Exploitability Score
4.9
Impact Score
10.0
CvssVersion
2.0

Exploit Intelligence

EPSS Score
6.39%
Probability of exploitation in next 30 days
EPSS Percentile
92.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0639 is in the 67th percentile among its peer group of 8,915 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (15)

microsoftpatch availablevia msrc
Product: cm1 xinetd 2.3.15-13 on CBL Mariner 1.0Fixed in: 2.3.15-13
microsoftpatch availablevia msrc
Product: cbl2 xinetd 2.3.15-14 on CBL Mariner 2.0Fixed in: 2.3.15-14
microsoftpatch availablevia msrc
Product: azl3 xinetd 2.3.15-14 on Azure Linux 3.0Fixed in: 2.3.15-14
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 ARMFixed in: 2.3.15-13
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 x64Fixed in: 2.3.15-14
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 ARMFixed in: 2.3.15-14
microsoftpatch availablevia msrc
Product: 19214-16820Fixed in: 2.3.15-13
microsoftpatch availablevia msrc
Product: 19215-16823Fixed in: 2.3.15-14
microsoftpatch availablevia msrc
Product: 19216-17084Fixed in: 2.3.15-14
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 2.3.15-14
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 2.3.15-14
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 x64Fixed in: 2.3.15-13
redhatpatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: xinetd-2:2.3.14-39.el6_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: xinetd-2:2.3.14-20.el5_10
View patch

Vendor Advisories (3)

microsoft2024-Jun/CVE-2013-4342

CVE-2013-4342

Jun 11, 2024
microsoft2013-Oct/CVE-2013-4342Important

xinetd does not enforce the user and group configuration directives for TCPMUX services which causes these services to be run as root and makes it easier for remote attackers to gain privileges by leveraging another vulnerability in a service.

Oct 2, 2013
redhatCVE-2013-4342Moderate

xinetd: ignores user and group directives for tcpmux services

Aug 23, 2005

References

rhn.redhat.com / errata/RHSA-2013-1409.html
bugzilla.redhat.com / show_bug.cgi
ExploitPatch
github.com / xinetd-org/xinetd/pull/10
security.gentoo.org / glsa/201611-06