info: name:/etc/passwd File Owner and Permission Check author: songyaeji severity: high description:> If a user other than root can modify the /etc/passwd file, it may allow unauthorized shell access or privilege escalation. This template checks that the file is owned by root and has permission 644or less. reference: - https://isms.kisa.or.kr/main/csap/notice/ - Cloud Vulnerability Assessment Guide (2024) by KISA tags: linux,local,permission,file,passwd,compliance metadata: verified:true os: linux max-request:1 classification: cwe-id: CWE-732 cvss-metrics: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H cvss-score:7.0