CVE-2015-7496 describes a lock screen bypass vulnerability in GNOME Display Manager (gdm) versions prior to 3.18.2, affecting Fedora and other GNOME-based systems. This flaw allows a physically proximate attacker to bypass the lock screen by simply holding the Escape key. With a CVSS score of 7.2 (High), this vulnerability is easily exploitable with low attack complexity and no authentication required, leading to complete compromise of confidentiality, integrity, and availability. While there is no known active exploitation or publicly available exploit code in Metasploit or ExploitDB, the vulnerability has received some community attention and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
23CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:23:*:*:*:*:*:*:* | ||
<= 3.18.0CPE matchmatch criteria | cpe:2.3:a:gnome:gnome_display_manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.