Test document
View file | ||||
---|---|---|---|---|
|
Vlus
Nexus URL: TBD
There are 17 CVEs with a CVSS score >= 9.0. These are exceptions requested here:
Release 5: Akraino CVE Vulnerability Exception Request
CVE-ID | CVSS |
ATTACK
POC
ALERT
NVD | Fix/Notes | PACKAGES |
CVE-2005-2541 | 10.0 |
https://nvd.nist.gov/vuln/detail/CVE-2005-2541 | unfixed | tar |
CVE-2014-2830 | 10.0 |
https://nvd.nist.gov/vuln/detail/CVE-2014-2830 | unfixed | cifs-utils |
CVE-2016-1585 | 9.8 |
https://nvd.nist.gov/vuln/detail/CVE-2016-1585 | unfixed | libapparmor1 |
CVE-2017-17479 | 9.8 |
https://nvd.nist.gov/vuln/detail/CVE-2017-17479 | unfixed | libopenjp2-7 |
CVE-2017-9117 | 9.8 |
AV:N
POC
https://nvd.nist.gov/vuln/detail/CVE-2017-9117 | unfixed | libtiff5 |
CVE-2018-13410 | 9.8 |
https://nvd.nist.gov/vuln/detail/CVE-2018-13410 | unfixed | zip |
CVE-2019-1010022 | 9.8 |
AV:N
https://nvd.nist.gov/vuln/detail/CVE-2019-1010022 | unfixed | libc-bin, libc-dev-bin, libc-devtools, libc-l10n, libc6, libc6-dbg, libc6-dev, locales |
CVE-2019-8341 | 9.8 |
AV:N
POC
https://nvd.nist.gov/vuln/detail/CVE-2019-8341 | unfixed | python3-jinja2 |
CVE-2020-27619 | 9.8 |
https://nvd.nist.gov/vuln/detail/CVE-2020-27619 | unfixed | python3.9 |
CVE-2021-29462 | 9.8 |
https://nvd.nist.gov/vuln/detail/CVE-2021-29462 | unfixed | libixml10, libupnp13 |
CVE-2021-29921 | 9.8 |
AV:N
https://nvd.nist.gov/vuln/detail/CVE-2021-29921 | unfixed | python3.9 |
CVE-2021-30473 | 9.8 |
https://nvd.nist.gov/vuln/detail/CVE-2021-30473 | unfixed | libaom0 |
CVE-2021-30474 | 9.8 |
https://nvd.nist.gov/vuln/detail/CVE-2021-30474 | unfixed | libaom0 |
CVE-2021-30475 | 9.8 |
https://nvd.nist.gov/vuln/detail/CVE-2021-30475 | unfixed | libaom0 |
CVE-2021-30498 | 9.8 |
AV:N
https://nvd.nist.gov/vuln/detail/CVE-2021-30498 | unfixed | libcaca0 |
CVE-2021-30499 | 9.8 |
AV:N
https://nvd.nist.gov/vuln/detail/CVE-2021-30499 | unfixed | libcaca0 |
CVE-2021-3756 | 9.8 |
AV:N
https://nvd.nist.gov/vuln/detail/CVE-2021-3756 | unfixed | libmysofa1 |
CVE-2021-42377 | 9.8 |
https://nvd.nist.gov/vuln/detail/CVE-2021-42377 | unfixed | busybox |
CVE-2021-45951 | 9.8 |
AV:N
POC
https://nvd.nist.gov/vuln/detail/CVE-2021-45951 | unfixed | dnsmasq |
CVE-2021-45952 | 9.8 |
AV:N
https://nvd.nist.gov/vuln/detail/CVE-2021-45952 | unfixed | dnsmasq |
CVE-2021-45953 | 9.8 |
AV:N
https://nvd.nist.gov/vuln/detail/CVE-2021-45953 | unfixed | dnsmasq |
CVE-2021-45954 | 9.8 |
AV:N
POC
https://nvd.nist.gov/vuln/detail/CVE-2021-45954 | unfixed | dnsmasq |
CVE-2021-45955 | 9.8 |
AV:N
https://nvd.nist.gov/vuln/detail/CVE-2021-45955 | unfixed | dnsmasq |
CVE-2021-45956 | 9.8 |
AV:N
https://nvd.nist.gov/vuln/detail/CVE-2021-45956 | unfixed | dnsmasq |
CVE-2022-0318 | 9.8 |
AV:N
POC
https://nvd.nist.gov/vuln/detail/CVE-2022-0318 | unfixed | vim |
CVE-2022-23303 | 9.8 |
https://nvd.nist.gov/vuln/detail/CVE-2022-23303 | unfixed | hostapd, wpasupplicant |
CVE-2022-23304 | 9.8 |
https://nvd.nist.gov/vuln/detail/CVE-2022-23304 | unfixed | hostapd, wpasupplicant |
CVE-2021-22945 | 9.1 |
AV:N
POC
https://nvd.nist.gov/vuln/detail/CVE-2021-22945 | unfixed | curl |
CVE-2021-4048 | 9.1 |
https://nvd.nist.gov/vuln/detail/CVE-2021-4048 | unfixed | libblas3, liblapack3 |
CVE-2021-43400 | 9.1 |
https://nvd.nist.gov/vuln/detail/CVE-2021-43400 | unfixed | bluez |
Lynis
Nexus URL TBD
The initial results compare with the Lynis Incubation: PASS/FAIL Criteria, v1.0 as follows.
IoT Gateway
The Lynis Program Update test MUST pass with no errors.
Code Block |
---|
2022-03-29 22:55:42 Test: Checking for program update... 2022-03-29 22:55:43 Current installed version : 308 2022-03-29 22:55:43 Latest stable version : 307 2022-03-29 22:55:43 No Lynis update available. |
...
PC/Server for robot control
The Lynis Program Update test MUST pass with no errors.
Code Block |
---|
2022-03-23 05:13:56 Test: Checking for program update... 2022-03-23 05:14:03 Current installed version : 308 2022-03-23 05:14:03 Latest stable version : 307 2022-03-23 05:14:03 No Lynis update available |
...