LiveActive security incident?Get immediate response
CVE Record

CVE-2021-32000: clone-master-clean-up: dangerous file system operations

A UNIX Symbolic Link (Symlink) Following vulnerability in the clone-master-clean-up.sh script of clone-master-clean-up in SUSE Linux Enterprise Server 12 SP3, SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allows local attackers to delete arbitrary files. This issue affects: SUSE Linux Enterprise Server 12 SP3 clone-master-clean-up version 1.6-4.6.1 and prior versions. SUSE Linux Enterprise Server 15 SP1 clone-master-clean-up version 1.6-3.9.1 and prior versions. openSUSE Factory clone-master-clean-up version 1.6-1.4 and prior versions.

LowCVSS 3.2Not KEV-listedUpdated
Glexia's TakeAutomated analysislow

Security readout for executives and security teams

Plain-English summary

CVE-2021-32000 is a low-severity file deletion issue in SUSE's clone-master-clean-up script. If an attacker can operate in the required local/physical context and trigger user interaction, symlink handling may cause unintended deletion of arbitrary files.

Executive priority

Handle through normal patch governance unless these systems are highly shared or physically accessible. Business urgency is low, but arbitrary file deletion can still disrupt hosts or provisioning workflows if affected systems remain unpatched.

Technical view

The clone-master-clean-up.sh script has a UNIX symlink-following weakness during filesystem cleanup. Affected clone-master-clean-up versions are listed for SLES 12 SP3, SLES 15 SP1, and openSUSE Factory. CVSS 3.1 is 3.2 with no confidentiality impact and low integrity/availability impact.

Likely exposure

Exposure appears limited to systems running the affected clone-master-clean-up package on the named SUSE or openSUSE releases. The CVSS vector indicates physical access and user interaction, so remote internet-facing exposure is not supported by the provided sources.

Exploitation context

The provided sources do not report active exploitation, and KEV is false. The record describes local attackers, while the CVSS vector lists physical access and user interaction. No public exploit status is established in the bundle.

Researcher notes

Evidence is limited to the CVE record and SUSE Bugzilla reference. The bundle names affected versions but does not provide detailed exploit mechanics, fixed versions, or operational mitigations. Avoid assuming broader SUSE release impact beyond the listed products.

Mitigation direction

  • Inventory SUSE and openSUSE hosts for clone-master-clean-up package usage.
  • Check SUSE or openSUSE vendor guidance for fixed package versions.
  • Update affected clone-master-clean-up packages when a vendor fix is available.
  • Restrict local/physical access to systems until remediation is confirmed.

Validation and detection

  • Confirm OS release matches SLES 12 SP3, SLES 15 SP1, or openSUSE Factory.
  • Check installed clone-master-clean-up package version against affected versions in the CVE record.
  • Verify vendor advisory status before declaring remediation complete.
  • Review local cleanup-script usage on affected images or templates.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2021-32000 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Low
CVSS
3.2 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
3.2CVSS 3.1LowCVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L0.72.5Primary CVE score

Vulnerability scoring details

Base CVSS 3.1 score

3.2Low
CVSS 3.1 vector shape for CVE-2021-32000Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
SUSESUSE Linux Enterprise Server 12 SP3clone-master-clean-upListed
SUSESUSE Linux Enterprise Server 15 SP1clone-master-clean-upListed
openSUSEFactoryclone-master-clean-upListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.