Pacemaker
Vendor:
First CVE: Nov 23, 2013 · Active for 12 years
10
Total CVEs
More Total CVEs than 88% of tracked products
1.4
Avg CVEs / Year
Higher CVE frequency than 56% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 33% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Pacemaker over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 23, 2013
12 years ago
Most Recent CVE
Oct 18, 2021
1,740 days ago
CVE Severity & Scoring
Pacemaker10 CVEs
40%
60%
All CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local5 (50.0%)
Network3 (30.0%)
Unknown2 (20.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (80.0%)
High0 (0.0%)
Unknown2 (20.0%)
User Interaction
None7 (70.0%)
Unknown2 (20.0%)
Required1 (10.0%)
Privileges Required
Low4 (40.0%)
High1 (10.0%)
None3 (30.0%)
Unknown2 (20.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-3885HIGH A use-after-free flaw was found in pacemaker up to and including version 2.0.1 which could result in certain sensitive information to be leaked via the system logs. | Apr 18, 2019 | 7.5 | 26 | NO | NO |
CVE-2018-16877HIGH A flaw was found in the way pacemaker's client-server authentication was implemented in versions up to and including 2.0.0. A local attacker could use this flaw, and combine it wit | Apr 18, 2019 | 7.8 | 25 | NO | NO |
CVE-2016-7035HIGH An authorization flaw was found in Pacemaker before 1.1.16, where it did not properly guard its IPC interface. An attacker with an unprivileged account on a Pacemaker node could us | Sep 10, 2018 | 7.8 | 25 | NO | NO |
CVE-2020-25654HIGH An ACL bypass flaw was found in pacemaker. An attacker having a local account on the cluster and in the haclient group could use IPC communication with various daemons directly to | Nov 24, 2020 | 7.2 | 24 | NO | NO |
CVE-2010-2496MEDIUM stonith-ng in pacemaker and cluster-glue passed passwords as commandline parameters, making it possible for local attackers to gain access to passwords of the HA stack and potentia | Oct 18, 2021 | 5.5 | 20 | NO | NO |
CVE-2018-16878MEDIUM A flaw was found in pacemaker up to and including version 2.0.1. An insufficient verification inflicted preference of uncontrolled processes can lead to DoS | Apr 18, 2019 | 5.5 | 20 | NO | NO |
CVE-2016-7797HIGH Pacemaker before 1.1.15, when using pacemaker remote, might allow remote attackers to cause a denial of service (node disconnection) via an unauthenticated connection. | Mar 24, 2017 | 7.5 | 20 | NO | NO |
CVE-2015-1867HIGH Pacemaker before 1.1.13 does not properly evaluate added nodes, which allows remote read-only users to gain privileges via an acl command. | Aug 12, 2015 | 7.5 | 20 | NO | NO |
CVE-2011-5271MEDIUM Pacemaker before 1.1.6 configure script creates temporary files insecurely | Nov 12, 2019 | 5.5 | 19 | NO | NO |
CVE-2013-0281MEDIUM Pacemaker 1.1.10, when remote Cluster Information Base (CIB) configuration or resource management is enabled, does not limit the duration of connections to the blocking sockets, wh | Nov 23, 2013 | 4.3 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Pacemaker
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.0.5 | 1 | 7.2 | 2.0% | 0 | 0 |
| 1.1.10 | 1 | 4.3 | 3.0% | 0 | 0 |