Severity: High
ID: 238807
File Name: tencentos_TSSA_2023_0339.nasl
Version: 1.3
Type: local
Family: Tencent Local Security Checks
Published: 6/16/2025
Updated: 11/23/2025
Supported Sensors: Nessus
Risk Factor: Critical
Score: 9.8
Risk Factor: High
Base Score: 7.2
Temporal Score: 6.3
Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSS Score Source: CVE-2022-29581
Risk Factor: High
Base Score: 8.8
Temporal Score: 8.4
Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Temporal Vector: CVSS:3.0/E:H/RL:O/RC:C
CVSS Score Source: CVE-2022-2196
Risk Factor: High
Base Score: 8.7
Threat Score: 8.7
Threat Vector: CVSS:4.0/E:A
Vector: CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L
CVSS Score Source: CVE-2021-22543
CPE: cpe:/o:tencent:tencentos_server:2, p-cpe:/a:tencent:tencentos_server:kernel
Required KB Items: Host/local_checks_enabled, Host/cpu, Host/etc/os-release, Host/TencentOS/rpm-list
Exploit Available: true
Exploit Ease: Exploits are available
Patch Publication Date: 5/6/2024
Vulnerability Publication Date: 5/6/2024
CISA Known Exploited Vulnerability Due Dates: 5/16/2022, 6/13/2022
CANVAS (CANVAS)
Core Impact
Metasploit (Dirty Pipe Local Privilege Escalation via CVE-2022-0847)
CVE: CVE-2020-27820, CVE-2021-0920, CVE-2021-20321, CVE-2021-22543, CVE-2021-38160, CVE-2021-38199, CVE-2021-45868, CVE-2022-0617, CVE-2022-0847, CVE-2022-0850, CVE-2022-20421, CVE-2022-2196, CVE-2022-2639, CVE-2022-29581, CVE-2022-3567, CVE-2022-3586, CVE-2022-4129, CVE-2022-41858, CVE-2022-4378, CVE-2023-0045, CVE-2023-0394, CVE-2023-1076, CVE-2023-20938, CVE-2023-2269, CVE-2023-2513, CVE-2023-30456, CVE-2023-31436, CVE-2023-32269, CVE-2023-35001