Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-45593

Опубликовано: 05 мар. 2024
Источник: nvd
CVSS3: 6.8
EPSS Низкий

Описание

A CWE-184 “Incomplete List of Disallowed Inputs” vulnerability in the embedded Chromium browser (concerning the handling of alternative URLs, other than “ http://localhost” ) allows a physical attacker to read arbitrary files on the file system, alter the configuration of the embedded browser, and have other unspecified impacts to the confidentiality, integrity, and availability of the device. This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ailux:imx6:*:*:*:*:*:*:*:*
Версия до 1.0.7-2 (исключая)

EPSS

Процентиль: 30%
0.00107
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-184
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 6.8
github
почти 2 года назад

A CWE-693 “Protection Mechanism Failure” vulnerability in the embedded Chromium browser (concerning the handling of alternative URLs, other than “ http://localhost” http://localhost” ) allows a physical attacker to read arbitrary files on the file system, alter the configuration of the embedded browser, and have other unspecified impacts to the confidentiality, integrity, and availability of the device. This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2.

EPSS

Процентиль: 30%
0.00107
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-184
NVD-CWE-noinfo