CVE-2003-1358 describes a privilege escalation vulnerability in HP-UX versions 10.0 through 11.22. The rs.F300 utility, operating with elevated privileges, improperly uses the PATH environment variable to locate and execute programs like 'rm'. This allows a local attacker to manipulate their PATH to point to a malicious 'rm' program, thereby gaining root privileges. With a CVSS score of 7.2, this vulnerability is considered high severity due to its local attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, an ExploitDB entry (EDB-22248) exists, and the vulnerability has garnered significant community discussion, indicating awareness and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.00CPE matchmatch criteria | cpe:2.3:o:hp:hp-ux:10.00:*:*:*:*:*:*:* | ||
10.01CPE matchmatch criteria | cpe:2.3:o:hp:hp-ux:10.01:*:*:*:*:*:*:* | ||
10.08CPE matchmatch criteria | cpe:2.3:o:hp:hp-ux:10.08:*:*:*:*:*:*:* | ||
10.09CPE matchmatch criteria | cpe:2.3:o:hp:hp-ux:10.09:*:*:*:*:*:*:* | ||
10.10CPE matchmatch criteria | cpe:2.3:o:hp:hp-ux:10.10:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.