Description
Incorrect access control in the SDAgent component of Shirt Pocket SuperDuper! v3.10 allows attackers to escalate privileges to root due to the improper use of a setuid binary.
Published: 2025-12-01
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 05 Dec 2025 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Shirt-pocket
Shirt-pocket superduper\!
CPEs cpe:2.3:a:shirt-pocket:superduper\!:3.10:*:*:*:*:*:*:*
Vendors & Products Shirt-pocket
Shirt-pocket superduper\!

Tue, 02 Dec 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Tue, 02 Dec 2025 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Shirt Pocket
Shirt Pocket superduper
Vendors & Products Shirt Pocket
Shirt Pocket superduper

Mon, 01 Dec 2025 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 01 Dec 2025 15:45:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the SDAgent component of Shirt Pocket SuperDuper! v3.10 allows attackers to escalate privileges to root due to the improper use of a setuid binary.
References

Subscriptions

Shirt-pocket Superduper\!
Shirt Pocket Superduper
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-12-01T19:49:22.061Z

Reserved: 2025-08-17T00:00:00.000Z

Link: CVE-2025-57489

cve-icon Vulnrichment

Updated: 2025-12-01T19:42:55.330Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-01T16:15:54.800

Modified: 2025-12-05T19:26:15.353

Link: CVE-2025-57489

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-02T12:15:28Z

Weaknesses