Vulnerability record · CVE-2000-0248 · published 24 April 2000
CVE-2000-0248: Red Hat Piranha LVS web GUI backdoor password allows remote command execution
Redhat · Linux
The web GUI shipped with the Red Hat Linux Piranha package for Linux Virtual Server (LVS) contains a hardcoded backdoor password. Anyone who knows or guesses that password can authenticate to the GUI and run arbitrary commands on the host. Because the interface is network-facing and the credential is built into the product, the flaw undermines the entire management plane of the load balancer.
Description
The web GUI for the Linux Virtual Server (LVS) software in the Red Hat Linux Piranha package has a backdoor password that allows remote attackers to execute arbitrary commands.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityThe flaw gives unauthenticated remote command execution on a network-facing management interface, and the CVSS 2.0 base score is 10.0 with a very high EPSS percentile.
What it is
The web GUI shipped with the Red Hat Linux Piranha package for Linux Virtual Server (LVS) contains a hardcoded backdoor password. Anyone who knows or guesses that password can authenticate to the GUI and run arbitrary commands on the host. Because the interface is network-facing and the credential is built into the product, the flaw undermines the entire management plane of the load balancer.
Impact
An attacker gains remote command execution with the privileges of the web GUI process, which on a load balancer typically means full control of the host. That allows configuration changes, traffic redirection, data theft, or use of the system as a pivot into the managed network.
Attack surface
Reachable over the network via the Piranha web GUI (CVSS 2.0 vector AV:N/AC:L/Au:N), so no prior authentication is required and no user interaction is needed. The only barrier is knowing the backdoor password.
Exploitation
No CISA KEV listing and no public exploit references are provided, but EPSS is 0.73662 (99.4th percentile), indicating a high modeled likelihood of exploitation. The vendor advisory is tagged Patch, so a fix exists.
What to do
- Apply the Red Hat Piranha patch referenced in the vendor advisory, or upgrade to a Piranha version that removes the backdoor password.
- If the Piranha web GUI is not required, disable or uninstall it and stop the associated service.
- Restrict network access to the Piranha GUI to trusted management hosts using firewall rules or network segmentation.
- Change any default or hardcoded credentials and audit the Piranha configuration for unauthorized accounts.
- Monitor the host for unexpected command execution or configuration changes originating from the GUI service.
Detection
- Review Piranha web GUI access logs for authentication attempts and successful logins, especially from unexpected source IPs.
- Hunt for processes spawned by the Piranha web GUI service (for example, shell or command interpreters) that are not part of normal load balancer operation.
- Compare current LVS and Piranha configuration against a known-good baseline to spot unauthorized changes.
- Alert on outbound connections or new listening services on the load balancer host that do not match its intended role.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://xforce.iss.net/alerts/advise46.php3 | PatchVendor Advisory |
| http://xforce.iss.net/alerts/advise46.php3 | PatchVendor Advisory |
Track CVE-2000-0248 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2000-0248), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.