CVE-2016-4484 is a vulnerability in the Debian cryptsetup package (2:1.7.3-2 and earlier) that allows physically proximate attackers to gain root shell access during boot-up on LUKS-encrypted systems. This medium-severity vulnerability (CVSS 6.8) has a physical attack vector, low complexity, and can lead to full compromise of confidentiality, integrity, and availability. While not listed on the KEV catalog and lacking public exploit code in Metasploit, Nuclei, or ExploitDB, it garnered significant community discussion and media coverage at the time of its discovery.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.1.7.3-2CPE matchmatch criteria | cpe:2.3:a:cryptsetup_project:cryptsetup:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.