← Vulnerability feed

Vulnerability record · CVE-2000-0248 · published 24 April 2000

CVE-2000-0248: Red Hat Piranha LVS web GUI backdoor password allows remote command execution

Redhat · Linux

The web GUI shipped with the Red Hat Linux Piranha package for Linux Virtual Server (LVS) contains a hardcoded backdoor password. Anyone who knows or guesses that password can authenticate to the GUI and run arbitrary commands on the host. Because the interface is network-facing and the credential is built into the product, the flaw undermines the entire management plane of the load balancer.

10.0 CVSS 2.0 High EPSS 74% · top 0.5%
10.0CVSS 2.0 base score
74%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
16 Jun 2026Last modified by NVD

Description

The web GUI for the Linux Virtual Server (LVS) software in the Red Hat Linux Piranha package has a backdoor password that allows remote attackers to execute arbitrary commands.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

critical priorityThe flaw gives unauthenticated remote command execution on a network-facing management interface, and the CVSS 2.0 base score is 10.0 with a very high EPSS percentile.

What it is

The web GUI shipped with the Red Hat Linux Piranha package for Linux Virtual Server (LVS) contains a hardcoded backdoor password. Anyone who knows or guesses that password can authenticate to the GUI and run arbitrary commands on the host. Because the interface is network-facing and the credential is built into the product, the flaw undermines the entire management plane of the load balancer.

Impact

An attacker gains remote command execution with the privileges of the web GUI process, which on a load balancer typically means full control of the host. That allows configuration changes, traffic redirection, data theft, or use of the system as a pivot into the managed network.

Attack surface

Reachable over the network via the Piranha web GUI (CVSS 2.0 vector AV:N/AC:L/Au:N), so no prior authentication is required and no user interaction is needed. The only barrier is knowing the backdoor password.

Exploitation

No CISA KEV listing and no public exploit references are provided, but EPSS is 0.73662 (99.4th percentile), indicating a high modeled likelihood of exploitation. The vendor advisory is tagged Patch, so a fix exists.

What to do

  • Apply the Red Hat Piranha patch referenced in the vendor advisory, or upgrade to a Piranha version that removes the backdoor password.
  • If the Piranha web GUI is not required, disable or uninstall it and stop the associated service.
  • Restrict network access to the Piranha GUI to trusted management hosts using firewall rules or network segmentation.
  • Change any default or hardcoded credentials and audit the Piranha configuration for unauthorized accounts.
  • Monitor the host for unexpected command execution or configuration changes originating from the GUI service.

Detection

  • Review Piranha web GUI access logs for authentication attempts and successful logins, especially from unexpected source IPs.
  • Hunt for processes spawned by the Piranha web GUI service (for example, shell or command interpreters) that are not part of normal load balancer operation.
  • Compare current LVS and Piranha configuration against a known-good baseline to spot unauthorized changes.
  • Alert on outbound connections or new listening services on the load balancer host that do not match its intended role.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2000-0248 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2005-3625Easy software products cups vulnerabilityXpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of servic…EPSS 3.8%10.0CVE-2004-0902Mozilla vulnerabilityMultiple heap-based buffer overflows in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote att…EPSS 10%10.0CVE-2004-0903Mozilla vulnerabilityStack-based buffer overflow in the writeGroup function in nsVCardObj.cpp for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Th…EPSS 9.7%10.0CVE-2004-1025Enlightenment imlib vulnerabilityMultiple heap-based buffer overflows in imlib 1.9.14 and earlier, which is used by gkrellm and several window managers, allow remote attackers to cau…EPSS 5.2%10.0CVE-2004-1026Enlightenment imlib vulnerabilityMultiple integer overflows in the image handler for imlib 1.9.14 and earlier, which is used by gkrellm and several window managers, allow remote atta…EPSS 4.9%10.0CVE-2004-0904Mozilla firefox vulnerabilityInteger overflow in the bitmap (BMP) decoder for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow r…EPSS 8.0%10.0CVE-2003-0248Redhat linux vulnerabilityThe mxcsr code in Linux kernel 2.4 allows attackers to modify CPU state registers via a malformed address.EPSS 3.7%10.0CVE-2003-0041Mit kerberos ftp client os command injection vulnerabilityKerberos FTP client allows remote FTP sites to execute arbitrary code via a pipe (|) character in a filename that is retrieved by the client.EPSS 3.5%

Source: NIST National Vulnerability Database (record CVE-2000-0248), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.