CVE-2012-2314 describes a vulnerability in the Anaconda bootloader configuration module (pyanaconda/bootloader.py) affecting Fedora Project Anaconda, where /etc/grub.d is assigned insecure 755 permissions. This allows local attackers to access password hashes, enabling brute-force password guessing. The vulnerability has a low severity CVSS score of 2.1 (AV:L/AC:L/Au:N/C:P/I:N/A:N), indicating a local attack vector with low complexity and a potential impact of partial confidentiality loss. There is no evidence of active exploitation, no known exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage, suggesting it is not a widely exploited or discussed threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:fedoraproject:anaconda:-:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.