Pacemaker

Vendor:

First CVE: Nov 23, 2013 · Active for 12 years

10
Total CVEs
More Total CVEs than 88% of tracked products
1.4
Avg CVEs / Year
Higher CVE frequency than 56% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 33% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Pacemaker over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 23, 2013
12 years ago
Most Recent CVE
Oct 18, 2021
1,740 days ago

CVE Severity & Scoring

Pacemaker10 CVEs
All CVEs352,231 CVEs
MediumHigh
Attack Vector
Local5 (50.0%)
Network3 (30.0%)
Unknown2 (20.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (80.0%)
High0 (0.0%)
Unknown2 (20.0%)
User Interaction
None7 (70.0%)
Unknown2 (20.0%)
Required1 (10.0%)
Privileges Required
Low4 (40.0%)
High1 (10.0%)
None3 (30.0%)
Unknown2 (20.0%)

Top CVEs

Signals from CVEs in this product scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A use-after-free flaw was found in pacemaker up to and including version 2.0.1 which could result in certain sensitive information to be leaked via the system logs.
Apr 18, 20197.526NONO
A flaw was found in the way pacemaker's client-server authentication was implemented in versions up to and including 2.0.0. A local attacker could use this flaw, and combine it wit
Apr 18, 20197.825NONO
An authorization flaw was found in Pacemaker before 1.1.16, where it did not properly guard its IPC interface. An attacker with an unprivileged account on a Pacemaker node could us
Sep 10, 20187.825NONO
An ACL bypass flaw was found in pacemaker. An attacker having a local account on the cluster and in the haclient group could use IPC communication with various daemons directly to
Nov 24, 20207.224NONO
stonith-ng in pacemaker and cluster-glue passed passwords as commandline parameters, making it possible for local attackers to gain access to passwords of the HA stack and potentia
Oct 18, 20215.520NONO
A flaw was found in pacemaker up to and including version 2.0.1. An insufficient verification inflicted preference of uncontrolled processes can lead to DoS
Apr 18, 20195.520NONO
Pacemaker before 1.1.15, when using pacemaker remote, might allow remote attackers to cause a denial of service (node disconnection) via an unauthenticated connection.
Mar 24, 20177.520NONO
Pacemaker before 1.1.13 does not properly evaluate added nodes, which allows remote read-only users to gain privileges via an acl command.
Aug 12, 20157.520NONO
Pacemaker before 1.1.6 configure script creates temporary files insecurely
Nov 12, 20195.519NONO
Pacemaker 1.1.10, when remote Cluster Information Base (CIB) configuration or resource management is enabled, does not limit the duration of connections to the blocking sockets, wh
Nov 23, 20134.319NONO

Exploit Exposure

Signals from CVEs in this product scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (10 CVEs).

Media Mentions

Signals from CVEs in this product scope (10 CVEs).

Top CNAs Publishing CVEs For Pacemaker

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.0.517.22.0%00
1.1.1014.33.0%00