CRITICAL

CVE-2021-38759

CVSS v3

9.8

CRITICAL

EPSS Score

33.9%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

Raspberry Pi OS through 5.10 has the raspberry default password for the pi account. If not changed, attackers can gain administrator privileges.

Technical details

Published
12/7/2021

Frequently asked questions

What is CVE-2021-38759?

Raspberry Pi OS through 5.10 has the raspberry default password for the pi account. If not changed, attackers can gain administrator privileges.

Is CVE-2021-38759 actively exploited?

Active exploitation of CVE-2021-38759 has not been confirmed. The EPSS score is 33.9%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2021-38759?

CVE-2021-38759 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2021-38759 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.