LiveActive security incident?Get immediate response
CVE Record

CVE-2020-27985: Security Onion v2 prior to 2.3.10 has an incorrect sudo configuration, which allows the administrative user...

Security Onion v2 prior to 2.3.10 has an incorrect sudo configuration, which allows the administrative user to obtain root access without using the sudo password by editing and executing /home/<user>/SecurityOnion/setup/so-setup.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

This flaw lets a Security Onion administrative user turn that access into root control on affected v2 systems before 2.3.10. It is not described as remotely exploitable in the provided sources, but it matters because Security Onion often protects monitoring and detection infrastructure.

Executive priority

Address during the next security maintenance window, faster for production monitoring nodes or shared admin environments. The business risk is control of detection infrastructure after administrative account compromise, not a proven remote mass-exploitation campaign.

Technical view

CVE-2020-27985 is an incorrect sudo configuration in Security Onion v2 prior to 2.3.10. The issue allowed the administrative user to gain root privileges through a setup script path. The public bundle provides no CVSS score, CWE, KEV listing, or confirmed active exploitation evidence.

Likely exposure

Exposure is limited to Security Onion v2 deployments earlier than 2.3.10 where an administrative user account exists. The evidence does not identify other affected products, internet-facing attack requirements, or unauthenticated access paths.

Exploitation context

The provided sources describe local privilege escalation from Security Onion administrative access to root. There is no KEV entry and no cited evidence of active exploitation in the bundle. Treat compromise of a Security Onion admin account as a potential full-host compromise on affected versions.

Researcher notes

The source bundle is sparse: no CVSS, CWE, or formal affected CPE data is provided. Analysis should stay scoped to Security Onion v2 before 2.3.10 and the documented sudo misconfiguration. Do not infer broader product impact without vendor confirmation.

Mitigation direction

  • Upgrade Security Onion v2 to 2.3.10 or later using vendor release guidance.
  • Review sudo configuration for unintended passwordless root paths.
  • Restrict and monitor administrative access to Security Onion hosts.
  • Check vendor advisories and release notes for any additional hardening guidance.

Validation and detection

  • Inventory Security Onion v2 systems and identify versions earlier than 2.3.10.
  • Compare local sudo policy against the vendor-fixed configuration.
  • Review administrative account access logs for unexpected setup or maintenance activity.
  • Confirm monitoring systems remain trusted after remediation.
Prepared
Confidence
medium
Sources
5

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

description · low confidence lookup

Credential and access behavior lookup

The CVE wording references authentication or credential exposure, so valid-account and credential-access review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2020-27985 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
4Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.