CVE-2022-29800
MEDIUM 4.7EPSS 7.2%
A time-of-check-time-of-use (TOCTOU) race condition vulnerability was found in networkd-dispatcher. This flaw exists because there is a certain time between the scripts being discovered and them being run. An attacker can abuse this vulnerability to replace scripts that networkd-dispatcher believes to be owned by root with ones that are not.
- CVSS v3.1
- 4.7 MEDIUM
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N - CVSS v3.1
- 4.7 MEDIUM
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N - EPSS
- 7.16% chance of exploitation in the next 30 days, 94th percentile
- Published
- 2022-09-21
- Updated
- 2025-05-28
Proof-of-concept exploits (4)
- DDNvR/privelege_escalation0★ · 2023-09-05
- jfrog/nimbuspwn-tools63★ · 2022-04-28
- ngtuonghung/nimbuspwn-CVE-2022-29800-CVE-2022-29799
- joshuavanderpoll/NimbusPWN-CVE-2022-29799-29800