CVE-2020-28046: Pax Prolinos

High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.

An issue was discovered in ProlinOS through 2.4.161.8859R. An attacker with local code execution privileges as a normal user (MAINAPP) can escalate to root privileges by exploiting the setuid installation of the xtables-multi binary and leveraging the ip6tables --modprobe switch.

Affected products

  • Pax Prolinos: up to and including 2.4.161.8859r

Published 2020-11-02. Last modified 2026-06-17.