Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-23299

Опубликовано: 23 мая 2023
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

The permission system implemented and enforced by the GarminOS TVM component in CIQ API version 1.0.0 through 4.1.7 can be bypassed entirely. A malicious application with specially crafted code and data sections could access restricted CIQ modules, call their functions and disclose sensitive data such as user profile information and GPS coordinates, among others.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:garmin:connect-iq:*:*:*:*:*:*:*:*
Версия от 1.0.0 (включая) до 4.1.7 (включая)

EPSS

Процентиль: 31%
0.00116
Низкий

7.5 High

CVSS3

Дефекты

NVD-CWE-noinfo
CWE-863

Связанные уязвимости

CVSS3: 7.5
github
больше 2 лет назад

The permission system implemented and enforced by the GarminOS TVM component in CIQ API version 1.0.0 through 4.1.7 can be bypassed entirely. A malicious application with specially crafted code and data sections could access restricted CIQ modules, call their functions and disclose sensitive data such as user profile information and GPS coordinates, among others.

EPSS

Процентиль: 31%
0.00116
Низкий

7.5 High

CVSS3

Дефекты

NVD-CWE-noinfo
CWE-863