CVE-2014-0748
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
27/12/2014
Last modified:
12/04/2025
Description
apinit on Cray devices with CLE before 4.2.UP02 and 5.x before 5.1.UP00 does not use alpsauth data to validate the UID in a launch message, which allows local users to gain privileges via a modified aprun program, aka ID FN5912.
Impact
Base Score 2.0
7.20
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:cray:cray_linux_environment:*:*:*:*:*:*:*:* | 4.2 (including) | |
| cpe:2.3:o:cray:cray_linux_environment:5.1:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



