Search

Find a vulnerability

Search criteria

    21 vulnerabilities by linuxfoundation

    CVE-2024-9802 (GCVE-0-2024-9802)

    Vulnerability from cvelistv5 – Published: 2024-10-10 07:41 – Updated: 2024-10-10 14:22
    VLAI
    Title
    Conformance validation endpoint discloses detail about service to unauthenticated users
    Summary
    The conformance validation endpoint is public so everybody can verify the conformance of onboarded services. The response could contain specific information about the service, including available endpoints, and swagger. It could advise about the running version of a service to an attacker. The attacker could also check if a service is running.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-10 13:45 UTC
    CWE
    • CWE-312 - Cleartext Storage of Sensitive Information
    References
    Impacted products
    Vendor Product Version
    Open Mainframe Project Zowe Affected: 2.11.0 , < 2.17.0 (semver)
    Create a notification for this product.
    linuxfoundation zowe_api_mediation_layer Affected: 2.11.0 , < 2.17.0 (semver)
        cpe:2.3:a:linuxfoundation:zowe_api_mediation_layer:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:linuxfoundation:zowe_api_mediation_layer:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "zowe_api_mediation_layer",
                "vendor": "linuxfoundation",
                "versions": [
                  {
                    "lessThan": "2.17.0",
                    "status": "affected",
                    "version": "2.11.0",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-9802",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-10T13:45:19.081095Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-312",
                    "description": "CWE-312 Cleartext Storage of Sensitive Information",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-10T14:22:43.244Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Zowe",
              "vendor": "Open Mainframe Project",
              "versions": [
                {
                  "lessThan": "2.17.0",
                  "status": "affected",
                  "version": "2.11.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Pablo Hernan Carle"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Pavel Jare\u0161"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The conformance validation endpoint is public so everybody can verify the conformance of onboarded services. The response could contain specific information about the service, including available endpoints, and swagger. It could advise about the running version of a service to an attacker. The attacker could also check if a service is running."
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "value": "There are no known exploits of this issue however exploits targeting this issue are publicly available."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-10-10T07:41:03.374Z",
            "orgId": "b1336bef-059d-4e13-b11b-9a6ef21b3c78",
            "shortName": "Zowe"
          },
          "references": [
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/zowe/api-layer"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "There is a fix since version 2.17.0, authentication is required for the endpoints."
            }
          ],
          "title": "Conformance validation endpoint discloses detail about service to unauthenticated users",
          "workarounds": [
            {
              "lang": "en",
              "value": "No workaround is available."
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b1336bef-059d-4e13-b11b-9a6ef21b3c78",
        "assignerShortName": "Zowe",
        "cveId": "CVE-2024-9802",
        "datePublished": "2024-10-10T07:41:03.374Z",
        "dateReserved": "2024-10-10T07:41:03.236Z",
        "dateUpdated": "2024-10-10T14:22:43.244Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-9798 (GCVE-0-2024-9798)

    Vulnerability from cvelistv5 – Published: 2024-10-10 07:29 – Updated: 2024-10-10 14:21
    VLAI
    Title
    Health endpoint offers list of onboarded services to unauthenticated users
    Summary
    The health endpoint is public so everybody can see a list of all services. It is potentially valuable information for attackers.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-10 14:16 UTC
    CWE
    • CWE-312 - Cleartext Storage of Sensitive Information
    References
    Impacted products
    Vendor Product Version
    Open Mainframe Project Zowe Affected: 2.0.0 , < 2.18.0 (semver)
    Affected: 1.0.0 , < 1.28.8 (semver)
    Create a notification for this product.
    linuxfoundation zowe_api_mediation_layer Affected: 2.0.0 , < 2.18.0 (semver)
    Affected: 1.0.0 , < 1.28.8 (semver)
        cpe:2.3:a:linuxfoundation:zowe_api_mediation_layer:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:linuxfoundation:zowe_api_mediation_layer:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "zowe_api_mediation_layer",
                "vendor": "linuxfoundation",
                "versions": [
                  {
                    "lessThan": "2.18.0",
                    "status": "affected",
                    "version": "2.0.0",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "1.28.8",
                    "status": "affected",
                    "version": "1.0.0",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-9798",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-10T14:16:37.423471Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-312",
                    "description": "CWE-312 Cleartext Storage of Sensitive Information",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-10T14:21:58.664Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Zowe",
              "vendor": "Open Mainframe Project",
              "versions": [
                {
                  "lessThan": "2.18.0",
                  "status": "affected",
                  "version": "2.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "1.28.8",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Pablo Hernan Carle"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Pavel Jare\u0161"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The health endpoint is public so everybody can see a list of all services. It is potentially valuable information for attackers."
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "value": "There are no known exploits of this issue however exploits targeting this issue are publicly available."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H/E:F/RL:T/RC:C/CR:H/IR:H/AR:M/MAV:N/MAC:L/MPR:N/MUI:N/MS:C/MC:H/MI:H/MA:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-10-10T07:29:10.066Z",
            "orgId": "b1336bef-059d-4e13-b11b-9a6ef21b3c78",
            "shortName": "Zowe"
          },
          "references": [
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/zowe/api-layer"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "In version 2.18.0 set configuration property `apiml.health.protected` to `true` to require authentication or upgrade to version 3."
            }
          ],
          "title": "Health endpoint offers list of onboarded services to unauthenticated users",
          "workarounds": [
            {
              "lang": "en",
              "value": "No workaround is available."
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b1336bef-059d-4e13-b11b-9a6ef21b3c78",
        "assignerShortName": "Zowe",
        "cveId": "CVE-2024-9798",
        "datePublished": "2024-10-10T07:29:10.066Z",
        "dateReserved": "2024-10-10T07:29:09.962Z",
        "dateUpdated": "2024-10-10T14:21:58.664Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-20089 (GCVE-0-2024-20089)

    Vulnerability from cvelistv5 – Published: 2024-09-02 02:07 – Updated: 2024-09-03 14:14
    VLAI
    Summary
    In wlan, there is a possible denial of service due to incorrect error handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08861558; Issue ID: MSV-1526.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-03 14:13 UTC
    CWE
    • CWE-703 - Improper Check or Handling of Exceptional Conditions
    • CWE-754 - Improper Check for Unusual or Exceptional Conditions
    Impacted products
    Vendor Product Version
    MediaTek, Inc. MT6835, MT6878, MT6886, MT6897, MT6980, MT6985, MT6989, MT6990, MT8678, MT8775, MT8792, MT8796 Affected: Android 13.0, 14.0 / Yocto 2.6, 3.3, 4.0 / RDK-B 22Q3
    Create a notification for this product.
    mediatek mt6835 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt6835:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt6878 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt6878:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt6886 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt6886:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt6897 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt6897:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt6980 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt6980:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt6985 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt6985:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt6989 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt6989:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt6990 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt6990:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8678 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8678:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8775 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8775:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8792 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8792:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8796 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8796:-:*:*:*:*:*:*:*
    Create a notification for this product.
    google android Affected: 13.0
    Affected: 14.0
        cpe:2.3:o:google:android:13.0:-:*:*:*:*:*:*
        cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*
    Create a notification for this product.
    linuxfoundation yocto Affected: 2.6
    Affected: 3.3
    Affected: 4.0
        cpe:2.3:a:linuxfoundation:yocto:2.6:*:*:*:*:*:*:*
        cpe:2.3:a:linuxfoundation:yocto:3.3:*:*:*:*:*:*:*
        cpe:2.3:a:linuxfoundation:yocto:4.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt6835:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt6835",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt6878:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt6878",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt6886:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt6886",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt6897:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt6897",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt6980:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt6980",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt6985:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt6985",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt6989:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt6989",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt6990:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt6990",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8678:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8678",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8775:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8775",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8792:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8792",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8796:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8796",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:google:android:13.0:-:*:*:*:*:*:*",
                  "cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "android",
                "vendor": "google",
                "versions": [
                  {
                    "status": "affected",
                    "version": "13.0"
                  },
                  {
                    "status": "affected",
                    "version": "14.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:linuxfoundation:yocto:2.6:*:*:*:*:*:*:*",
                  "cpe:2.3:a:linuxfoundation:yocto:3.3:*:*:*:*:*:*:*",
                  "cpe:2.3:a:linuxfoundation:yocto:4.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "yocto",
                "vendor": "linuxfoundation",
                "versions": [
                  {
                    "status": "affected",
                    "version": "2.6"
                  },
                  {
                    "status": "affected",
                    "version": "3.3"
                  },
                  {
                    "status": "affected",
                    "version": "4.0"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7.5,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "NONE",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-20089",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-03T14:13:06.564754Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-754",
                    "description": "CWE-754 Improper Check for Unusual or Exceptional Conditions",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-03T14:14:40.888Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "MT6835, MT6878, MT6886, MT6897, MT6980, MT6985, MT6989, MT6990, MT8678, MT8775, MT8792, MT8796",
              "vendor": "MediaTek, Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "Android 13.0, 14.0 / Yocto 2.6, 3.3, 4.0 / RDK-B 22Q3"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In wlan, there is a possible denial of service due to incorrect error handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08861558; Issue ID: MSV-1526."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-703",
                  "description": "CWE-703 Improper Check or Handling of Exceptional Conditions",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-09-02T02:07:37.971Z",
            "orgId": "ee979b05-11f8-4f25-a7e0-a1fa9c190374",
            "shortName": "MediaTek"
          },
          "references": [
            {
              "url": "https://corp.mediatek.com/product-security-bulletin/September-2024"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ee979b05-11f8-4f25-a7e0-a1fa9c190374",
        "assignerShortName": "MediaTek",
        "cveId": "CVE-2024-20089",
        "datePublished": "2024-09-02T02:07:37.971Z",
        "dateReserved": "2023-11-02T13:35:35.174Z",
        "dateUpdated": "2024-09-03T14:14:40.888Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-41265 (GCVE-0-2024-41265)

    Vulnerability from cvelistv5 – Published: 2024-08-01 00:00 – Updated: 2024-08-02 15:47
    VLAI
    Summary
    A TLS certificate verification issue discovered in cortex v0.42.1 allows attackers to obtain sensitive information via the makeOperatorRequest function.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-08-02 15:28 UTC
    CWE
    • n/a
    • CWE-599 - Missing Validation of OpenSSL Certificate
    Impacted products
    Vendor Product Version
    linuxfoundation cortex Affected: 0 , ≤ 0.42.1 (custom)
        cpe:2.3:a:linuxfoundation:cortex:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:linuxfoundation:cortex:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "cortex",
                "vendor": "linuxfoundation",
                "versions": [
                  {
                    "lessThanOrEqual": "0.42.1",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "NONE",
                  "baseScore": 7.5,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-41265",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-08-02T15:28:04.553238Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-599",
                    "description": "CWE-599 Missing Validation of OpenSSL Certificate",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-02T15:47:54.333Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A TLS certificate verification issue discovered in cortex v0.42.1 allows attackers to obtain sensitive information via the makeOperatorRequest function."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-08-01T16:01:22.165Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://gist.github.com/nyxfqq/1a8237f3f9cf793c6433f08b17d1593c"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2024-41265",
        "datePublished": "2024-08-01T00:00:00.000Z",
        "dateReserved": "2024-07-18T00:00:00.000Z",
        "dateUpdated": "2024-08-02T15:47:54.333Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-6834 (GCVE-0-2024-6834)

    Vulnerability from cvelistv5 – Published: 2024-07-17 14:44 – Updated: 2024-08-13 21:00
    VLAI
    Title
    Imperative Local Command Injection allows Activity Masking
    Summary
    A vulnerability in APIML Spring Cloud Gateway which leverages user privileges by unexpected signing proxied request by Zowe's client certificate. This allows access to a user to the endpoints requiring an internal client certificate without any credentials. It could lead to managing components in there and allow an attacker to handle the whole communication including user credentials.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-07-17 15:12 UTC
    CWE
    • CWE-250 - Execution with Unnecessary Privileges
    References
    Impacted products
    Vendor Product Version
    Open Mainframe Project Zowe Affected: 2.4.0 , < 2.14.0 (semver)
    Create a notification for this product.
    linuxfoundation zowe_api_mediation_layer Affected: 2.4.0 , < 2.14.0 (semver)
        cpe:2.3:a:linuxfoundation:zowe_api_mediation_layer:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:linuxfoundation:zowe_api_mediation_layer:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "zowe_api_mediation_layer",
                "vendor": "linuxfoundation",
                "versions": [
                  {
                    "lessThan": "2.14.0",
                    "status": "affected",
                    "version": "2.4.0",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-6834",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-07-17T15:12:02.406649Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-250",
                    "description": "CWE-250 Execution with Unnecessary Privileges",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-13T21:00:07.595Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T21:45:38.340Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "product",
                  "x_transferred"
                ],
                "url": "https://github.com/zowe/api-layer"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Zowe",
              "vendor": "Open Mainframe Project",
              "versions": [
                {
                  "lessThan": "2.14.0",
                  "status": "affected",
                  "version": "2.4.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Pavel Jares"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Andrej Chmelo"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability in APIML Spring Cloud Gateway which leverages user privileges by unexpected signing proxied request by Zowe\u0027s client certificate. This allows access to a user to the endpoints requiring an internal client certificate without any credentials. It could lead to managing components in there and allow an attacker to handle the whole communication including user credentials."
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "value": "There are no known exploits of this issue however exploits targeting this issue are publicly available."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "NONE",
                "baseScore": 9,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "LOW",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H/E:F/RL:T/RC:C/CR:H/IR:H/AR:M/MAV:N/MAC:L/MPR:N/MUI:N/MS:C/MC:H/MI:H/MA:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-07-17T14:44:06.283Z",
            "orgId": "b1336bef-059d-4e13-b11b-9a6ef21b3c78",
            "shortName": "Zowe"
          },
          "references": [
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/zowe/api-layer"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "This issue is fixed in the APIML 2.14.4 (Zowe 2.14) and later. Fixed by https://github.com/zowe/api-layer/pull/3203 and https://github.com/zowe/api-layer/pull/3273"
            }
          ],
          "title": "Imperative Local Command Injection allows Activity Masking"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b1336bef-059d-4e13-b11b-9a6ef21b3c78",
        "assignerShortName": "Zowe",
        "cveId": "CVE-2024-6834",
        "datePublished": "2024-07-17T14:44:06.283Z",
        "dateReserved": "2024-07-17T14:44:06.201Z",
        "dateUpdated": "2024-08-13T21:00:07.595Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-5187 (GCVE-0-2024-5187)

    Vulnerability from cvelistv5 – Published: 2024-06-06 18:45 – Updated: 2024-08-01 21:03
    VLAI
    Title
    Arbitrary File Overwrite in download_model_with_test_data in onnx/onnx
    Summary
    A vulnerability in the `download_model_with_test_data` function of the onnx/onnx framework, version 1.16.0, allows for arbitrary file overwrite due to inadequate prevention of path traversal attacks in malicious tar files. This vulnerability enables attackers to overwrite any file on the system, potentially leading to remote code execution, deletion of system, personal, or application files, thus impacting the integrity and availability of the system. The issue arises from the function's handling of tar file extraction without performing security checks on the paths within the tar file, as demonstrated by the ability to overwrite the `/home/kali/.ssh/authorized_keys` file by specifying an absolute path in the malicious tar file.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-06-07 18:47 UTC
    CWE
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
    Impacted products
    Vendor Product Version
    onnx onnx/onnx Affected: unspecified , ≤ latest (custom)
    Create a notification for this product.
    linuxfoundation onnx Affected: 1.16.0 , < * (custom)
        cpe:2.3:a:linuxfoundation:onnx:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:linuxfoundation:onnx:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "onnx",
                "vendor": "linuxfoundation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "1.16.0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-5187",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-06-07T18:47:07.750405Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-07T18:53:05.608Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T21:03:10.963Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://huntr.com/bounties/50235ebd-3410-4ada-b064-1a648e11237e"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "onnx/onnx",
              "vendor": "onnx",
              "versions": [
                {
                  "lessThanOrEqual": "latest",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability in the `download_model_with_test_data` function of the onnx/onnx framework, version 1.16.0, allows for arbitrary file overwrite due to inadequate prevention of path traversal attacks in malicious tar files. This vulnerability enables attackers to overwrite any file on the system, potentially leading to remote code execution, deletion of system, personal, or application files, thus impacting the integrity and availability of the system. The issue arises from the function\u0027s handling of tar file extraction without performing security checks on the paths within the tar file, as demonstrated by the ability to overwrite the `/home/kali/.ssh/authorized_keys` file by specifying an absolute path in the malicious tar file."
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-06-06T18:45:19.456Z",
            "orgId": "c09c270a-b464-47c1-9133-acb35b22c19a",
            "shortName": "@huntr_ai"
          },
          "references": [
            {
              "url": "https://huntr.com/bounties/50235ebd-3410-4ada-b064-1a648e11237e"
            }
          ],
          "source": {
            "advisory": "50235ebd-3410-4ada-b064-1a648e11237e",
            "discovery": "EXTERNAL"
          },
          "title": "Arbitrary File Overwrite in download_model_with_test_data in onnx/onnx"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "c09c270a-b464-47c1-9133-acb35b22c19a",
        "assignerShortName": "@huntr_ai",
        "cveId": "CVE-2024-5187",
        "datePublished": "2024-06-06T18:45:19.456Z",
        "dateReserved": "2024-05-21T20:40:57.332Z",
        "dateUpdated": "2024-08-01T21:03:10.963Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-37152 (GCVE-0-2024-37152)

    Vulnerability from cvelistv5 – Published: 2024-06-06 15:33 – Updated: 2024-08-02 03:50
    VLAI
    Title
    Unauthenticated Access to sensitive settings in Argo CD
    Summary
    Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The vulnerability allows unauthorized access to the sensitive settings exposed by /api/v1/settings endpoint without authentication. All sensitive settings are hidden except passwordPattern. This vulnerability is fixed in 2.11.3, 2.10.12, and 2.9.17.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-06-10 13:49 UTC
    CWE
    • CWE-287 - Improper Authentication
    • CWE-306 - Missing Authentication for Critical Function
    References
    Impacted products
    Vendor Product Version
    argoproj argo-cd Affected: >= 2.9.3, < 2.9.17
    Affected: >= 2.10.0, < 2.10.12
    Affected: >= 2.11.0, < 2.11.3
    Create a notification for this product.
    linuxfoundation argo-cd Affected: 2.9.3 , < 2.9.17 (custom)
    Affected: 2.10.0 , < 2.10.2 (custom)
    Affected: 2.11.0 , < 2.11.3 (custom)
        cpe:2.3:a:linuxfoundation:argo-cd:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:linuxfoundation:argo-cd:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "argo-cd",
                "vendor": "linuxfoundation",
                "versions": [
                  {
                    "lessThan": "2.9.17",
                    "status": "affected",
                    "version": "2.9.3",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "2.10.2",
                    "status": "affected",
                    "version": "2.10.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "2.11.3",
                    "status": "affected",
                    "version": "2.11.0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-37152",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-06-10T13:49:11.409850Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-10T13:59:44.786Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T03:50:55.946Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "https://github.com/argoproj/argo-cd/security/advisories/GHSA-87p9-x75h-p4j2",
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://github.com/argoproj/argo-cd/security/advisories/GHSA-87p9-x75h-p4j2"
              },
              {
                "name": "https://github.com/argoproj/argo-cd/commit/256d90178b11b04bc8174d08d7b663a2a7b1771b",
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://github.com/argoproj/argo-cd/commit/256d90178b11b04bc8174d08d7b663a2a7b1771b"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "argo-cd",
              "vendor": "argoproj",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003e= 2.9.3, \u003c 2.9.17"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 2.10.0, \u003c 2.10.12"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 2.11.0, \u003c 2.11.3"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The vulnerability allows unauthorized access to the sensitive settings exposed by  /api/v1/settings endpoint without authentication. All sensitive settings are hidden except passwordPattern. This vulnerability is fixed in 2.11.3, 2.10.12, and 2.9.17."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-287",
                  "description": "CWE-287: Improper Authentication",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-306",
                  "description": "CWE-306: Missing Authentication for Critical Function",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-06-06T15:33:29.843Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/argoproj/argo-cd/security/advisories/GHSA-87p9-x75h-p4j2",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/argoproj/argo-cd/security/advisories/GHSA-87p9-x75h-p4j2"
            },
            {
              "name": "https://github.com/argoproj/argo-cd/commit/256d90178b11b04bc8174d08d7b663a2a7b1771b",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/argoproj/argo-cd/commit/256d90178b11b04bc8174d08d7b663a2a7b1771b"
            }
          ],
          "source": {
            "advisory": "GHSA-87p9-x75h-p4j2",
            "discovery": "UNKNOWN"
          },
          "title": "Unauthenticated Access to sensitive settings in Argo CD"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2024-37152",
        "datePublished": "2024-06-06T15:33:29.843Z",
        "dateReserved": "2024-06-03T17:29:38.328Z",
        "dateUpdated": "2024-08-02T03:50:55.946Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-37018 (GCVE-0-2024-37018)

    Vulnerability from cvelistv5 – Published: 2024-05-31 00:35 – Updated: 2025-02-13 15:59
    VLAI
    Summary
    The OpenDaylight 0.15.3 controller allows topology poisoning via API requests because an application can manipulate the path that is taken by discovery packets.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-08-05 14:43 UTC
    CWE
    • n/a
    • CWE-648 - Incorrect Use of Privileged APIs
    Impacted products
    Vendor Product Version
    linuxfoundation opendaylight Affected: 0.15.3
        cpe:2.3:a:linuxfoundation:opendaylight:0.15.3:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T03:43:50.672Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jira.opendaylight.org/browse/DISCOVERY-2"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://mvnrepository.com/artifact/org.opendaylight.controller"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:linuxfoundation:opendaylight:0.15.3:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "opendaylight",
                "vendor": "linuxfoundation",
                "versions": [
                  {
                    "status": "affected",
                    "version": "0.15.3"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "NONE",
                  "baseScore": 9.1,
                  "baseSeverity": "CRITICAL",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-37018",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-08-05T14:43:23.057089Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-648",
                    "description": "CWE-648 Incorrect Use of Privileged APIs",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-05T15:36:36.384Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The OpenDaylight 0.15.3 controller allows topology poisoning via API requests because an application can manipulate the path that is taken by discovery packets."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-12-16T21:03:57.244Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://jira.opendaylight.org/browse/DISCOVERY-2"
            },
            {
              "url": "https://mvnrepository.com/artifact/org.opendaylight.controller"
            },
            {
              "url": "https://dl.acm.org/doi/10.1145/3658644.3690345"
            },
            {
              "url": "https://github.com/mzc796/marionette_onos"
            },
            {
              "url": "https://github.com/mzc796/marionette_odl"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2024-37018",
        "datePublished": "2024-05-31T00:35:10.757Z",
        "dateReserved": "2024-05-31T00:00:00.000Z",
        "dateUpdated": "2025-02-13T15:59:47.007Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-21662 (GCVE-0-2024-21662)

    Vulnerability from cvelistv5 – Published: 2024-03-18 18:42 – Updated: 2024-08-01 22:27
    VLAI
    Title
    Argo CD vulnerable to Bypassing of Rate Limit and Brute Force Protection Using Cache Overflow
    Summary
    Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.8.13, 2.9.9, and 2.10.4, an attacker can effectively bypass the rate limit and brute force protections by exploiting the application's weak cache-based mechanism. This loophole in security can be combined with other vulnerabilities to attack the default admin account. This flaw undermines a patch for CVE-2020-8827 intended to protect against brute-force attacks. The application's brute force protection relies on a cache mechanism that tracks login attempts for each user. This cache is limited to a `defaultMaxCacheSize` of 1000 entries. An attacker can overflow this cache by bombarding it with login attempts for different users, thereby pushing out the admin account's failed attempts and effectively resetting the rate limit for that account. This is a severe vulnerability that enables attackers to perform brute force attacks at an accelerated rate, especially targeting the default admin account. Users should upgrade to version 2.8.13, 2.9.9, or 2.10.4 to receive a patch.
    SSVC
    Exploitation: poc Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-07-16 00:19 UTC
    CWE
    • CWE-307 - Improper Restriction of Excessive Authentication Attempts
    Impacted products
    Vendor Product Version
    argoproj argo-cd Affected: < 2.8.13
    Affected: >= 2.9.0, < 2.9.9
    Affected: >= 2.10.0, < 2.10.4
    Create a notification for this product.
    linuxfoundation argo-cd Affected: 2.9.0 , < 2.9.9 (custom)
        cpe:2.3:a:linuxfoundation:argo-cd:2.9.0:-:*:*:*:*:*:*
    Create a notification for this product.
    linuxfoundation argo-cd Affected: 2.10.0
        cpe:2.3:a:linuxfoundation:argo-cd:2.10.0:*:*:*:*:*:*:*
    Create a notification for this product.
    linuxfoundation argo-cd Affected: 0 , < 2.8.13 (custom)
        cpe:2.3:a:linuxfoundation:argo-cd:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:linuxfoundation:argo-cd:2.9.0:-:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "argo-cd",
                "vendor": "linuxfoundation",
                "versions": [
                  {
                    "lessThan": "2.9.9",
                    "status": "affected",
                    "version": "2.9.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:linuxfoundation:argo-cd:2.10.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "argo-cd",
                "vendor": "linuxfoundation",
                "versions": [
                  {
                    "status": "affected",
                    "version": "2.10.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:linuxfoundation:argo-cd:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "argo-cd",
                "vendor": "linuxfoundation",
                "versions": [
                  {
                    "lessThan": "2.8.13",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-21662",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-07-16T00:19:37.829646Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-07-16T00:24:27.974Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T22:27:36.084Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "https://github.com/argoproj/argo-cd/security/advisories/GHSA-2vgg-9h6w-m454",
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://github.com/argoproj/argo-cd/security/advisories/GHSA-2vgg-9h6w-m454"
              },
              {
                "name": "https://github.com/argoproj/argo-cd/commit/17b0df1168a4c535f6f37e95f25ed7cd81e1fa4d",
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://github.com/argoproj/argo-cd/commit/17b0df1168a4c535f6f37e95f25ed7cd81e1fa4d"
              },
              {
                "name": "https://github.com/argoproj/argo-cd/commit/6e181d72b31522f886a2afa029d5b26d7912ec7b",
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://github.com/argoproj/argo-cd/commit/6e181d72b31522f886a2afa029d5b26d7912ec7b"
              },
              {
                "name": "https://github.com/argoproj/argo-cd/commit/cebb6538f7944c87ca2fecb5d17f8baacc431456",
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://github.com/argoproj/argo-cd/commit/cebb6538f7944c87ca2fecb5d17f8baacc431456"
              },
              {
                "name": "https://argo-cd.readthedocs.io/en/stable/security_considerations/#cve-2020-8827-insufficient-anti-automationanti-brute-force",
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://argo-cd.readthedocs.io/en/stable/security_considerations/#cve-2020-8827-insufficient-anti-automationanti-brute-force"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "argo-cd",
              "vendor": "argoproj",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 2.8.13"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 2.9.0, \u003c 2.9.9"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 2.10.0, \u003c 2.10.4"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.8.13, 2.9.9, and 2.10.4, an attacker can effectively bypass the rate limit and brute force protections by exploiting the application\u0027s weak cache-based mechanism. This loophole in security can be combined with other vulnerabilities to attack the default admin account. This flaw undermines a patch for CVE-2020-8827 intended to protect against brute-force attacks. The application\u0027s brute force protection relies on a cache mechanism that tracks login attempts for each user. This cache is limited to a `defaultMaxCacheSize` of 1000 entries. An attacker can overflow this cache by bombarding it with login attempts for different users, thereby pushing out the admin account\u0027s failed attempts and effectively resetting the rate limit for that account. This is a severe vulnerability that enables attackers to perform brute force attacks at an accelerated rate, especially targeting the default admin account. Users should upgrade to version 2.8.13, 2.9.9, or 2.10.4 to receive a patch."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-307",
                  "description": "CWE-307: Improper Restriction of Excessive Authentication Attempts",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-03-18T18:42:04.701Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/argoproj/argo-cd/security/advisories/GHSA-2vgg-9h6w-m454",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/argoproj/argo-cd/security/advisories/GHSA-2vgg-9h6w-m454"
            },
            {
              "name": "https://github.com/argoproj/argo-cd/commit/17b0df1168a4c535f6f37e95f25ed7cd81e1fa4d",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/argoproj/argo-cd/commit/17b0df1168a4c535f6f37e95f25ed7cd81e1fa4d"
            },
            {
              "name": "https://github.com/argoproj/argo-cd/commit/6e181d72b31522f886a2afa029d5b26d7912ec7b",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/argoproj/argo-cd/commit/6e181d72b31522f886a2afa029d5b26d7912ec7b"
            },
            {
              "name": "https://github.com/argoproj/argo-cd/commit/cebb6538f7944c87ca2fecb5d17f8baacc431456",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/argoproj/argo-cd/commit/cebb6538f7944c87ca2fecb5d17f8baacc431456"
            },
            {
              "name": "https://argo-cd.readthedocs.io/en/stable/security_considerations/#cve-2020-8827-insufficient-anti-automationanti-brute-force",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://argo-cd.readthedocs.io/en/stable/security_considerations/#cve-2020-8827-insufficient-anti-automationanti-brute-force"
            }
          ],
          "source": {
            "advisory": "GHSA-2vgg-9h6w-m454",
            "discovery": "UNKNOWN"
          },
          "title": "Argo CD vulnerable to Bypassing of Rate Limit and Brute Force Protection Using Cache Overflow"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2024-21662",
        "datePublished": "2024-03-18T18:42:04.701Z",
        "dateReserved": "2023-12-29T16:10:20.367Z",
        "dateUpdated": "2024-08-01T22:27:36.084Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-51699 (GCVE-0-2023-51699)

    Vulnerability from cvelistv5 – Published: 2024-03-15 19:08 – Updated: 2024-08-02 22:40
    VLAI
    Title
    OS Command Injection for Fluid Users with JuicefsRuntime
    Summary
    Fluid is an open source Kubernetes-native Distributed Dataset Orchestrator and Accelerator for data-intensive applications. An OS command injection vulnerability within the Fluid project's JuicefsRuntime can potentially allow an authenticated user, who has the authority to create or update the K8s CRD Dataset/JuicefsRuntime, to execute arbitrary OS commands within the juicefs related containers. This could lead to unauthorized access, modification or deletion of data. Users who're using versions < 0.9.3 with JuicefsRuntime should upgrade to v0.9.3.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-03-21 16:25 UTC
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    References
    Impacted products
    Vendor Product Version
    fluid-cloudnative fluid Affected: < 0.9.3
    Create a notification for this product.
    linuxfoundation fluid Affected: 0 , < 0.9.3 (custom)
        cpe:2.3:a:linuxfoundation:fluid:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:linuxfoundation:fluid:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "fluid",
                "vendor": "linuxfoundation",
                "versions": [
                  {
                    "lessThan": "0.9.3",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-51699",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-03-21T16:25:23.783810Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-07-25T16:22:05.659Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T22:40:34.213Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "https://github.com/fluid-cloudnative/fluid/security/advisories/GHSA-wx8q-4gm9-rj2g",
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://github.com/fluid-cloudnative/fluid/security/advisories/GHSA-wx8q-4gm9-rj2g"
              },
              {
                "name": "https://github.com/fluid-cloudnative/fluid/commit/e0184cff8790ad000c3e8943392c7f544fad7d66",
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://github.com/fluid-cloudnative/fluid/commit/e0184cff8790ad000c3e8943392c7f544fad7d66"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "fluid",
              "vendor": "fluid-cloudnative",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 0.9.3"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Fluid is an open source Kubernetes-native Distributed Dataset Orchestrator and Accelerator for data-intensive applications. An OS command injection vulnerability within the Fluid project\u0027s JuicefsRuntime can potentially allow an authenticated user, who has the authority to create or update the K8s CRD Dataset/JuicefsRuntime, to execute arbitrary OS commands within the juicefs related containers. This could lead to unauthorized access, modification or deletion of data. Users who\u0027re using versions \u003c 0.9.3 with JuicefsRuntime should upgrade to v0.9.3."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "LOCAL",
                "availabilityImpact": "NONE",
                "baseScore": 4,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78: Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-03-15T19:08:19.193Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/fluid-cloudnative/fluid/security/advisories/GHSA-wx8q-4gm9-rj2g",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/fluid-cloudnative/fluid/security/advisories/GHSA-wx8q-4gm9-rj2g"
            },
            {
              "name": "https://github.com/fluid-cloudnative/fluid/commit/e0184cff8790ad000c3e8943392c7f544fad7d66",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/fluid-cloudnative/fluid/commit/e0184cff8790ad000c3e8943392c7f544fad7d66"
            }
          ],
          "source": {
            "advisory": "GHSA-wx8q-4gm9-rj2g",
            "discovery": "UNKNOWN"
          },
          "title": "OS Command Injection for Fluid Users with JuicefsRuntime"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2023-51699",
        "datePublished": "2024-03-15T19:08:19.193Z",
        "dateReserved": "2023-12-21T21:32:12.991Z",
        "dateUpdated": "2024-08-02T22:40:34.213Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-27318 (GCVE-0-2024-27318)

    Vulnerability from cvelistv5 – Published: 2024-02-23 17:37 – Updated: 2025-02-13 17:46
    VLAI
    Summary
    Versions of the package onnx before and including 1.15.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory. The vulnerability occurs as a bypass for the patch added for CVE-2022-25882.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-08-14 15:31 UTC
    CWE
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
    Impacted products
    Vendor Product Version
    onnx onnx Affected: 0 , ≤ 1.15.0 (semver)
    Create a notification for this product.
    linuxfoundation onnx Affected: 0 , ≤ 1.15.0 (semver)
        cpe:2.3:a:linuxfoundation:onnx:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T00:34:51.388Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://github.com/onnx/onnx/commit/66b7fb630903fdcf3e83b6b6d56d82e904264a20"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://security.snyk.io/vuln/SNYK-PYTHON-ONNX-2395479"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TFJJID2IZDOLFDMWVYTBDI75ZJQC6JOL/"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FGTBH5ZYL2LGYHIJDHN2MAUURIR5E7PY/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:linuxfoundation:onnx:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "onnx",
                "vendor": "linuxfoundation",
                "versions": [
                  {
                    "lessThanOrEqual": "1.15.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-27318",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-08-14T15:31:21.543853Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-14T15:46:57.827Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "onnx",
              "product": "onnx",
              "repo": "https://github.com/onnx/onnx",
              "vendor": "onnx",
              "versions": [
                {
                  "lessThanOrEqual": "1.15.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eVersions of the package onnx before and including 1.15.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory. The vulnerability occurs as a bypass for the patch added for CVE-2022-25882.\u003c/span\u003e\u003cbr\u003e"
                }
              ],
              "value": "Versions of the package onnx before and including 1.15.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory. The vulnerability occurs as a bypass for the patch added for CVE-2022-25882."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-126",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-126 Path Traversal"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-03-30T02:06:29.877Z",
            "orgId": "6f8de1f0-f67e-45a6-b68f-98777fdb759c",
            "shortName": "HiddenLayer"
          },
          "references": [
            {
              "url": "https://github.com/onnx/onnx/commit/66b7fb630903fdcf3e83b6b6d56d82e904264a20"
            },
            {
              "url": "https://security.snyk.io/vuln/SNYK-PYTHON-ONNX-2395479"
            },
            {
              "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TFJJID2IZDOLFDMWVYTBDI75ZJQC6JOL/"
            },
            {
              "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FGTBH5ZYL2LGYHIJDHN2MAUURIR5E7PY/"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "6f8de1f0-f67e-45a6-b68f-98777fdb759c",
        "assignerShortName": "HiddenLayer",
        "cveId": "CVE-2024-27318",
        "datePublished": "2024-02-23T17:37:36.715Z",
        "dateReserved": "2024-02-23T16:59:23.009Z",
        "dateUpdated": "2025-02-13T17:46:25.734Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-43637 (GCVE-0-2023-43637)

    Vulnerability from cvelistv5 – Published: 2023-09-21 13:20 – Updated: 2024-09-24 17:48
    VLAI
    Title
    Vault Key Partially Predetermined
    Summary
    Due to the implementation of "deriveVaultKey", prior to version 7.10, the generated vault key would always have the last 16 bytes predetermined to be "arfoobarfoobarfo". This issue happens because "deriveVaultKey" calls "retrieveCloudKey" (which will always return "foobarfoobarfoobarfoobarfoobarfo" as the key), and then merges the 32byte randomly generated key with this key (by takeing 16bytes from each, see "mergeKeys"). This makes the key a lot weaker. This issue does not persist in devices that were initialized on/after version 7.10, but devices that were initialized before that and updated to a newer version still have this issue. Roll an update that enforces the full 32bytes key usage.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-24 17:45 UTC
    CWE
    • CWE-321 - Use of Hard-coded Cryptographic Key
    References
    Impacted products
    Vendor Product Version
    LF-Edge, Zededa EVE OS Affected: 0 , < 7.10 (release)
    Create a notification for this product.
    linuxfoundation edge_virtualization_engine Affected: 0 , < 7.10 (custom)
        cpe:2.3:o:linuxfoundation:edge_virtualization_engine:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T19:44:43.811Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://asrg.io/security-advisories/cve-2023-43637/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:linuxfoundation:edge_virtualization_engine:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "edge_virtualization_engine",
                "vendor": "linuxfoundation",
                "versions": [
                  {
                    "lessThan": "7.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-43637",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-24T17:45:45.770173Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-24T17:48:30.086Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "EVE OS",
              "product": "EVE OS",
              "programFiles": [
                "https://github.com/lf-edge/eve/tree/master/pkg/pillar/cmd/vaultmgr/vaultmgr.go",
                "https://github.com/lf-edge/eve/tree/master/pkg/pillar/vault/key.go"
              ],
              "repo": "https://github.com/lf-edge/eve",
              "vendor": " LF-Edge, Zededa",
              "versions": [
                {
                  "lessThan": "7.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "release"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Ilay Levi"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\n\nDue to the implementation of \"deriveVaultKey\", prior to version 7.10, the generated vault key\nwould always have the last 16 bytes predetermined to be \"arfoobarfoobarfo\".\n\u003cbr\u003eThis issue happens because \"deriveVaultKey\" calls \"retrieveCloudKey\" (which will always\nreturn \"foobarfoobarfoobarfoobarfoobarfo\" as the key), and then merges the 32byte\nrandomly generated key with this key (by takeing 16bytes from each, see \"mergeKeys\").\n\u003cbr\u003eThis makes the key a lot weaker.\n\u003cbr\u003eThis issue does not persist in devices that were initialized on/after version 7.10, but devices\nthat were initialized before that and updated to a newer version still have this issue.\u003cbr\u003e\u003cbr\u003e\n\nRoll an update that enforces the full 32bytes key usage.\n\n\n\n\n\n\u003cbr\u003e"
                }
              ],
              "value": "\nDue to the implementation of \"deriveVaultKey\", prior to version 7.10, the generated vault key\nwould always have the last 16 bytes predetermined to be \"arfoobarfoobarfo\".\n\nThis issue happens because \"deriveVaultKey\" calls \"retrieveCloudKey\" (which will always\nreturn \"foobarfoobarfoobarfoobarfoobarfo\" as the key), and then merges the 32byte\nrandomly generated key with this key (by takeing 16bytes from each, see \"mergeKeys\").\n\nThis makes the key a lot weaker.\n\nThis issue does not persist in devices that were initialized on/after version 7.10, but devices\nthat were initialized before that and updated to a newer version still have this issue.\n\n\n\nRoll an update that enforces the full 32bytes key usage.\n\n\n\n\n\n\n"
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-115",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-115 Authentication Bypass"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-321",
                  "description": "CWE-321 Use of Hard-coded Cryptographic Key",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-09-28T05:39:38.194Z",
            "orgId": "c15abc07-96a9-4d11-a503-5d621bfe42ba",
            "shortName": "ASRG"
          },
          "references": [
            {
              "url": "https://asrg.io/security-advisories/cve-2023-43637/"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Vault Key Partially Predetermined",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "c15abc07-96a9-4d11-a503-5d621bfe42ba",
        "assignerShortName": "ASRG",
        "cveId": "CVE-2023-43637",
        "datePublished": "2023-09-21T13:20:05.473Z",
        "dateReserved": "2023-09-20T14:34:14.875Z",
        "dateUpdated": "2024-09-24T17:48:30.086Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-43631 (GCVE-0-2023-43631)

    Vulnerability from cvelistv5 – Published: 2023-09-21 13:17 – Updated: 2024-09-24 17:41
    VLAI
    Title
    SSH as Root Unlockable Without Triggering Measured Boot
    Summary
    On boot, the Pillar eve container checks for the existence and content of “/config/authorized_keys”. If the file is present, and contains a supported public key, the container will go on to open port 22 and enable sshd with the given keys as the authorized keys for root login. An attacker could easily add their own keys and gain full control over the system without triggering the “measured boot” mechanism implemented by EVE OS, and without marking the device as “UUD” (“Unknown Update Detected”). This is because the “/config” partition is not protected by “measured boot”, it is mutable, and it is not encrypted in any way. An attacker can gain full control over the device without changing the PCR values, thus not triggering the “measured boot” mechanism, and having full access to the vault. Note: This issue was partially fixed in these commits (after disclosure to Zededa), where the config partition measurement was added to PCR13: • aa3501d6c57206ced222c33aea15a9169d629141 • 5fef4d92e75838cc78010edaed5247dfbdae1889. This issue was made viable in version 9.0.0 when the calculation was moved to PCR14 but it was not included in the measured boot.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-24 17:19 UTC
    CWE
    • CWE-522 - Insufficiently Protected Credentials
    • CWE-922 - Insecure Storage of Sensitive Information
    References
    Impacted products
    Vendor Product Version
    LF-Edge, Zededa EVE OS Affected: 0 , < 8.6.0 (release)
    Affected: 9.0.0 , < 9.5.0 (release)
    Create a notification for this product.
    linuxfoundation edge_virtualization_engine Affected: 0 , < 8.6.0 (custom)
    Affected: 9.0.0 , < 9.5.0 (custom)
        cpe:2.3:o:linuxfoundation:edge_virtualization_engine:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T19:44:43.700Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://asrg.io/security-advisories/cve-2023-43631/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:linuxfoundation:edge_virtualization_engine:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "edge_virtualization_engine",
                "vendor": "linuxfoundation",
                "versions": [
                  {
                    "lessThan": "8.6.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "9.5.0",
                    "status": "affected",
                    "version": "9.0.0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-43631",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-24T17:19:48.322052Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-24T17:41:19.204Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "EVE OS",
              "product": "EVE OS",
              "programFiles": [
                "https://github.com/lf-edge/eve/tree/master/pkg/pillar/evetpm/tpm.go",
                "https://github.com/lf-edge/eve/tree/master/pkg/grub/rootfs.cfg"
              ],
              "repo": "https://github.com/lf-edge/eve",
              "vendor": " LF-Edge, Zededa",
              "versions": [
                {
                  "lessThan": "8.6.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "release"
                },
                {
                  "lessThan": "9.5.0",
                  "status": "affected",
                  "version": "9.0.0",
                  "versionType": "release"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Ilay Levi"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\n\nOn boot, the Pillar eve container checks for the existence and content of\n\u201c/config/authorized_keys\u201d.\n\u003cbr\u003eIf the file is present, and contains a supported public key, the container will go on to open\nport 22 and enable sshd with the given keys as the authorized keys for root login.\n\u003cbr\u003eAn attacker could easily add their own keys and gain full control over the system without\ntriggering the \u201cmeasured boot\u201d mechanism implemented by EVE OS, and without marking\nthe device as \u201cUUD\u201d (\u201cUnknown Update Detected\u201d).\n\u003cbr\u003eThis is because the \u201c/config\u201d partition is not protected by \u201cmeasured boot\u201d, it is mutable, and\nit is not encrypted in any way.\n\u003cbr\u003e\u003cbr\u003e\n\nAn attacker can gain full control over the device without changing the PCR values, thus not\ntriggering the \u201cmeasured boot\u201d mechanism, and having full access to the vault.\n\n\u003cbr\u003e\u003cbr\u003eNote:\n\u003cbr\u003eThis issue was partially fixed in these commits (after disclosure to Zededa), where the config\npartition measurement was added to PCR13:\n\u003cbr\u003e\u2022 aa3501d6c57206ced222c33aea15a9169d629141\n\u003cbr\u003e\u2022 5fef4d92e75838cc78010edaed5247dfbdae1889.\n\u003cbr\u003eThis issue was made viable in version 9.0.0 when the calculation was moved to PCR14 but it was not included in the measured boot."
                }
              ],
              "value": "\nOn boot, the Pillar eve container checks for the existence and content of\n\u201c/config/authorized_keys\u201d.\n\nIf the file is present, and contains a supported public key, the container will go on to open\nport 22 and enable sshd with the given keys as the authorized keys for root login.\n\nAn attacker could easily add their own keys and gain full control over the system without\ntriggering the \u201cmeasured boot\u201d mechanism implemented by EVE OS, and without marking\nthe device as \u201cUUD\u201d (\u201cUnknown Update Detected\u201d).\n\nThis is because the \u201c/config\u201d partition is not protected by \u201cmeasured boot\u201d, it is mutable, and\nit is not encrypted in any way.\n\n\n\n\nAn attacker can gain full control over the device without changing the PCR values, thus not\ntriggering the \u201cmeasured boot\u201d mechanism, and having full access to the vault.\n\n\n\nNote:\n\nThis issue was partially fixed in these commits (after disclosure to Zededa), where the config\npartition measurement was added to PCR13:\n\n\u2022 aa3501d6c57206ced222c33aea15a9169d629141\n\n\u2022 5fef4d92e75838cc78010edaed5247dfbdae1889.\n\nThis issue was made viable in version 9.0.0 when the calculation was moved to PCR14 but it was not included in the measured boot."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-115",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-115 Authentication Bypass"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-522",
                  "description": "CWE-522 Insufficiently Protected Credentials",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-922",
                  "description": "CWE-922 Insecure Storage of Sensitive Information",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-09-28T05:40:00.086Z",
            "orgId": "c15abc07-96a9-4d11-a503-5d621bfe42ba",
            "shortName": "ASRG"
          },
          "references": [
            {
              "url": "https://asrg.io/security-advisories/cve-2023-43631/"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "SSH as Root Unlockable Without Triggering Measured Boot",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "c15abc07-96a9-4d11-a503-5d621bfe42ba",
        "assignerShortName": "ASRG",
        "cveId": "CVE-2023-43631",
        "datePublished": "2023-09-21T13:17:00.528Z",
        "dateReserved": "2023-09-20T14:34:14.874Z",
        "dateUpdated": "2024-09-24T17:41:19.204Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-43635 (GCVE-0-2023-43635)

    Vulnerability from cvelistv5 – Published: 2023-09-20 14:58 – Updated: 2024-09-25 14:37
    VLAI
    Title
    Vault Key Sealed With SHA1 PCRs
    Summary
    Vault Key Sealed With SHA1 PCRs The measured boot solution implemented in EVE OS leans on a PCR locking mechanism. Different parts of the system update different PCR values in the TPM, resulting in a unique value for each PCR entry. These PCRs are then used in order to seal/unseal a key from the TPM which is used to encrypt/decrypt the “vault” directory. This “vault” directory is the most sensitive point in the system and as such, its content should be protected. This mechanism is noted in Zededa’s documentation as the “measured boot” mechanism, designed to protect said “vault”. The code that’s responsible for generating and fetching the key from the TPM assumes that SHA256 PCRs are used in order to seal/unseal the key, and as such their presence is being checked. The issue here is that the key is not sealed using SHA256 PCRs, but using SHA1 PCRs. This leads to several issues: • Machines that have their SHA256 PCRs enabled but SHA1 PCRs disabled, as well as not sealing their keys at all, meaning the “vault” is not protected from an attacker. • SHA1 is considered insecure and reduces the complexity level required to unseal the key in machines which have their SHA1 PCRs enabled. An attacker can very easily retrieve the contents of the “vault”, which will effectively render the “measured boot” mechanism meaningless.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-25 14:32 UTC
    CWE
    • CWE-522 - Insufficiently Protected Credentials
    • CWE-328 - Use of Weak Hash
    References
    Impacted products
    Vendor Product Version
    LF-Edge, Zededa EVE OS Affected: 0 , < 9.5.0 (release)
    Create a notification for this product.
    linuxfoundation edge_virtualization_engine Affected: 0 , < 9.5.0 (custom)
        cpe:2.3:o:linuxfoundation:edge_virtualization_engine:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2023-09-20 14:57
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T19:44:43.776Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://asrg.io/security-advisories/cve-2023-43635/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:linuxfoundation:edge_virtualization_engine:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "edge_virtualization_engine",
                "vendor": "linuxfoundation",
                "versions": [
                  {
                    "lessThan": "9.5.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-43635",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-25T14:32:23.099233Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-25T14:37:39.566Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "EVE OS",
              "product": "EVE OS",
              "programFiles": [
                "https://github.com/lf-edge/eve/blob/master/pkg/pillar/evetpm/tpm.go"
              ],
              "repo": "https://github.com/lf-edge/eve",
              "vendor": " LF-Edge, Zededa",
              "versions": [
                {
                  "lessThan": "9.5.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "release"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Ilay Levi"
            }
          ],
          "datePublic": "2023-09-20T14:57:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\n\nVault Key Sealed With SHA1 PCRs\n\n\n\u003cbr\u003e\u003cbr\u003e\n\nThe measured boot solution implemented in EVE OS leans on a PCR locking mechanism.\n\u003cbr\u003eDifferent parts of the system update different PCR values in the TPM, resulting in a unique\nvalue for each PCR entry.\n\u003cbr\u003eThese PCRs are then used in order to seal/unseal a key from the TPM which is used to\nencrypt/decrypt the \u201cvault\u201d directory.\n\u003cbr\u003eThis \u201cvault\u201d directory is the most sensitive point in the system and as such, its content should\nbe protected.\n\u003cbr\u003eThis mechanism is noted in Zededa\u2019s documentation as the \u201cmeasured boot\u201d mechanism,\ndesigned to protect said \u201cvault\u201d.\n\u003cbr\u003eThe code that\u2019s responsible for generating and fetching the key from the TPM assumes that\nSHA256 PCRs are used in order to seal/unseal the key, and as such their presence is being\nchecked.\n\u003cbr\u003eThe issue here is that the key is not sealed using SHA256 PCRs, but using SHA1 PCRs.\nThis leads to several issues:\n\u003cbr\u003e\u2022 Machines that have their SHA256 PCRs enabled but SHA1 PCRs disabled, as well\nas not sealing their keys at all, meaning the \u201cvault\u201d is not protected from an attacker.\n\u003cbr\u003e\u2022 SHA1 is considered insecure and reduces the complexity level required to unseal the\nkey in machines which have their SHA1 PCRs enabled.\u003cbr\u003e\u003cbr\u003e\n\nAn attacker can very easily retrieve the contents of the \u201cvault\u201d, which will effectively render\nthe \u201cmeasured boot\u201d mechanism meaningless.\n\n\n\n\n\u003cbr\u003e"
                }
              ],
              "value": "\nVault Key Sealed With SHA1 PCRs\n\n\n\n\n\n\nThe measured boot solution implemented in EVE OS leans on a PCR locking mechanism.\n\nDifferent parts of the system update different PCR values in the TPM, resulting in a unique\nvalue for each PCR entry.\n\nThese PCRs are then used in order to seal/unseal a key from the TPM which is used to\nencrypt/decrypt the \u201cvault\u201d directory.\n\nThis \u201cvault\u201d directory is the most sensitive point in the system and as such, its content should\nbe protected.\n\nThis mechanism is noted in Zededa\u2019s documentation as the \u201cmeasured boot\u201d mechanism,\ndesigned to protect said \u201cvault\u201d.\n\nThe code that\u2019s responsible for generating and fetching the key from the TPM assumes that\nSHA256 PCRs are used in order to seal/unseal the key, and as such their presence is being\nchecked.\n\nThe issue here is that the key is not sealed using SHA256 PCRs, but using SHA1 PCRs.\nThis leads to several issues:\n\n\u2022 Machines that have their SHA256 PCRs enabled but SHA1 PCRs disabled, as well\nas not sealing their keys at all, meaning the \u201cvault\u201d is not protected from an attacker.\n\n\u2022 SHA1 is considered insecure and reduces the complexity level required to unseal the\nkey in machines which have their SHA1 PCRs enabled.\n\n\n\nAn attacker can very easily retrieve the contents of the \u201cvault\u201d, which will effectively render\nthe \u201cmeasured boot\u201d mechanism meaningless.\n\n\n\n\n\n"
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-115",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-115 Authentication Bypass"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-522",
                  "description": "CWE-522 Insufficiently Protected Credentials",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-328",
                  "description": "CWE-328 Use of Weak Hash",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-09-28T05:36:04.512Z",
            "orgId": "c15abc07-96a9-4d11-a503-5d621bfe42ba",
            "shortName": "ASRG"
          },
          "references": [
            {
              "url": "https://asrg.io/security-advisories/cve-2023-43635/"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Vault Key Sealed With SHA1 PCRs",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "c15abc07-96a9-4d11-a503-5d621bfe42ba",
        "assignerShortName": "ASRG",
        "cveId": "CVE-2023-43635",
        "datePublished": "2023-09-20T14:58:07.687Z",
        "dateReserved": "2023-09-20T14:34:14.874Z",
        "dateUpdated": "2024-09-25T14:37:39.566Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-32811 (GCVE-0-2023-32811)

    Vulnerability from cvelistv5 – Published: 2023-09-04 02:28 – Updated: 2024-10-01 18:15
    VLAI
    Summary
    In connectivity system driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07929848; Issue ID: ALPS07929848.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-01 18:07 UTC
    CWE
    • Elevation of Privilege
    • CWE-787 - Out-of-bounds Write
    • CWE-20 - Improper Input Validation
    Impacted products
    Vendor Product Version
    MediaTek, Inc. MT2713, MT6779, MT6781, MT6785, MT6789, MT6833, MT6835, MT6853, MT6855, MT6873, MT8168, MT8175, MT8188, MT8195, MT8365, MT8666, MT8667, MT8673 Affected: Android 12.0, 13.0 / IOT-v23.0 / Yocto 4.0
    Create a notification for this product.
    linuxfoundation yocto Affected: 4.0
        cpe:2.3:a:linuxfoundation:yocto:4.0:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek iot_yocto Affected: 23.0
        cpe:2.3:a:mediatek:iot_yocto:23.0:*:*:*:*:*:*:*
    Create a notification for this product.
    google android Affected: 12.0
        cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
    Create a notification for this product.
    google android Affected: 13.0
        cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T15:25:37.093Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://corp.mediatek.com/product-security-bulletin/September-2023"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:linuxfoundation:yocto:4.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "yocto",
                "vendor": "linuxfoundation",
                "versions": [
                  {
                    "status": "affected",
                    "version": "4.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:mediatek:iot_yocto:23.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "iot_yocto",
                "vendor": "mediatek",
                "versions": [
                  {
                    "status": "affected",
                    "version": "23.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "android",
                "vendor": "google",
                "versions": [
                  {
                    "status": "affected",
                    "version": "12.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "android",
                "vendor": "google",
                "versions": [
                  {
                    "status": "affected",
                    "version": "13.0"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "LOCAL",
                  "availabilityImpact": "HIGH",
                  "baseScore": 6.7,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "HIGH",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-32811",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-01T18:07:49.242266Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-787",
                    "description": "CWE-787 Out-of-bounds Write",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              },
              {
                "descriptions": [
                  {
                    "cweId": "CWE-20",
                    "description": "CWE-20 Improper Input Validation",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-01T18:15:59.375Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "MT2713, MT6779, MT6781, MT6785, MT6789, MT6833, MT6835, MT6853, MT6855, MT6873, MT8168, MT8175, MT8188, MT8195, MT8365, MT8666, MT8667, MT8673",
              "vendor": "MediaTek, Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "Android 12.0, 13.0 / IOT-v23.0 / Yocto 4.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In connectivity system driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07929848; Issue ID: ALPS07929848."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Elevation of Privilege",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-09-04T02:28:18.886Z",
            "orgId": "ee979b05-11f8-4f25-a7e0-a1fa9c190374",
            "shortName": "MediaTek"
          },
          "references": [
            {
              "url": "https://corp.mediatek.com/product-security-bulletin/September-2023"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ee979b05-11f8-4f25-a7e0-a1fa9c190374",
        "assignerShortName": "MediaTek",
        "cveId": "CVE-2023-32811",
        "datePublished": "2023-09-04T02:28:18.886Z",
        "dateReserved": "2023-05-16T03:04:32.146Z",
        "dateUpdated": "2024-10-01T18:15:59.375Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-20850 (GCVE-0-2023-20850)

    Vulnerability from cvelistv5 – Published: 2023-09-04 02:28 – Updated: 2024-10-01 17:38
    VLAI
    Summary
    In imgsys_cmdq, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07340433; Issue ID: ALPS07340381.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-01 17:22 UTC
    CWE
    • Elevation of Privilege
    • CWE-787 - Out-of-bounds Write
    Impacted products
    Vendor Product Version
    MediaTek, Inc. MT2713, MT6895, MT6897, MT6983, MT8188, MT8195, MT8395, MT8781 Affected: Android 11.0, 12.0 / Linux 6.1 / IOT-v23.0 / Yocto 4.0
    Create a notification for this product.
    linuxfoundation yocto Affected: 4.0
        cpe:2.3:a:linuxfoundation:yocto:4.0:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek iot_yocto Affected: 23.0
        cpe:2.3:a:mediatek:iot_yocto:23.0:*:*:*:*:*:*:*
    Create a notification for this product.
    google android Affected: 11.0
        cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:*
    Create a notification for this product.
    google android Affected: 12.0
        cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 6.1
        cpe:2.3:o:linux:linux_kernel:6.1:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T09:14:41.111Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://corp.mediatek.com/product-security-bulletin/September-2023"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:linuxfoundation:yocto:4.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "yocto",
                "vendor": "linuxfoundation",
                "versions": [
                  {
                    "status": "affected",
                    "version": "4.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:mediatek:iot_yocto:23.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "iot_yocto",
                "vendor": "mediatek",
                "versions": [
                  {
                    "status": "affected",
                    "version": "23.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "android",
                "vendor": "google",
                "versions": [
                  {
                    "status": "affected",
                    "version": "11.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "android",
                "vendor": "google",
                "versions": [
                  {
                    "status": "affected",
                    "version": "12.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:6.1:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "status": "affected",
                    "version": "6.1"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "LOCAL",
                  "availabilityImpact": "HIGH",
                  "baseScore": 6.5,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "HIGH",
                  "scope": "UNCHANGED",
                  "userInteraction": "REQUIRED",
                  "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-20850",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-01T17:22:21.552027Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-787",
                    "description": "CWE-787 Out-of-bounds Write",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-01T17:38:18.992Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "MT2713, MT6895, MT6897, MT6983, MT8188, MT8195, MT8395, MT8781",
              "vendor": "MediaTek, Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "Android 11.0, 12.0 / Linux 6.1 / IOT-v23.0 / Yocto 4.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In imgsys_cmdq, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07340433; Issue ID: ALPS07340381."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Elevation of Privilege",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-09-04T02:28:05.423Z",
            "orgId": "ee979b05-11f8-4f25-a7e0-a1fa9c190374",
            "shortName": "MediaTek"
          },
          "references": [
            {
              "url": "https://corp.mediatek.com/product-security-bulletin/September-2023"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ee979b05-11f8-4f25-a7e0-a1fa9c190374",
        "assignerShortName": "MediaTek",
        "cveId": "CVE-2023-20850",
        "datePublished": "2023-09-04T02:28:05.423Z",
        "dateReserved": "2022-10-28T02:03:23.696Z",
        "dateUpdated": "2024-10-01T17:38:18.992Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-20849 (GCVE-0-2023-20849)

    Vulnerability from cvelistv5 – Published: 2023-09-04 02:28 – Updated: 2024-10-01 18:58
    VLAI
    Summary
    In imgsys_cmdq, there is a possible use after free due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07340433; Issue ID: ALPS07340350.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-01 18:46 UTC
    CWE
    • Elevation of Privilege
    • CWE-416 - Use After Free
    Impacted products
    Vendor Product Version
    MediaTek, Inc. MT2713, MT6895, MT6897, MT6983, MT8188, MT8195, MT8395, MT8781 Affected: Android 11.0, 12.0 / Linux 6.1 / IOT-v23.0 / Yocto 4.0
    Create a notification for this product.
    linuxfoundation yocto Affected: 4.0
        cpe:2.3:a:linuxfoundation:yocto:4.0:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek iot_yocto Affected: 23.0
        cpe:2.3:a:mediatek:iot_yocto:23.0:*:*:*:*:*:*:*
    Create a notification for this product.
    google android Affected: 11.0
        cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:*
    Create a notification for this product.
    google android Affected: 12.0
        cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 6.1
        cpe:2.3:o:linux:linux_kernel:6.1:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T09:14:41.136Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://corp.mediatek.com/product-security-bulletin/September-2023"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:linuxfoundation:yocto:4.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "yocto",
                "vendor": "linuxfoundation",
                "versions": [
                  {
                    "status": "affected",
                    "version": "4.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:mediatek:iot_yocto:23.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "iot_yocto",
                "vendor": "mediatek",
                "versions": [
                  {
                    "status": "affected",
                    "version": "23.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "android",
                "vendor": "google",
                "versions": [
                  {
                    "status": "affected",
                    "version": "11.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "android",
                "vendor": "google",
                "versions": [
                  {
                    "status": "affected",
                    "version": "12.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:6.1:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "status": "affected",
                    "version": "6.1"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "LOCAL",
                  "availabilityImpact": "HIGH",
                  "baseScore": 6.5,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "HIGH",
                  "scope": "UNCHANGED",
                  "userInteraction": "REQUIRED",
                  "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-20849",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-01T18:46:24.279622Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-416",
                    "description": "CWE-416 Use After Free",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-01T18:58:38.274Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "MT2713, MT6895, MT6897, MT6983, MT8188, MT8195, MT8395, MT8781",
              "vendor": "MediaTek, Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "Android 11.0, 12.0 / Linux 6.1 / IOT-v23.0 / Yocto 4.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In imgsys_cmdq, there is a possible use after free due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07340433; Issue ID: ALPS07340350."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Elevation of Privilege",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-09-04T02:28:03.822Z",
            "orgId": "ee979b05-11f8-4f25-a7e0-a1fa9c190374",
            "shortName": "MediaTek"
          },
          "references": [
            {
              "url": "https://corp.mediatek.com/product-security-bulletin/September-2023"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ee979b05-11f8-4f25-a7e0-a1fa9c190374",
        "assignerShortName": "MediaTek",
        "cveId": "CVE-2023-20849",
        "datePublished": "2023-09-04T02:28:03.822Z",
        "dateReserved": "2022-10-28T02:03:23.696Z",
        "dateUpdated": "2024-10-01T18:58:38.274Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-20805 (GCVE-0-2023-20805)

    Vulnerability from cvelistv5 – Published: 2023-08-07 03:21 – Updated: 2024-10-22 15:13
    VLAI
    Summary
    In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07199773; Issue ID: ALPS07326411.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-22 14:59 UTC
    CWE
    • Elevation of Privilege
    • CWE-787 - Out-of-bounds Write
    Impacted products
    Vendor Product Version
    MediaTek, Inc. MT2713, MT6879, MT6895, MT6983, MT8188, MT8195, MT8395, MT8673 Affected: Android 12.0, 13.0 / IOT-v23.0 (Yocto 4.0)
    Create a notification for this product.
    mediatek mt2713 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt2713:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt6879 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt6879:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt6895 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt6895:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt6983 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt6983:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8188 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8188:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8195 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8195:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8395 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8395:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8673 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8673:-:*:*:*:*:*:*:*
    Create a notification for this product.
    google android Affected: 12.0
    Affected: 13.0
        cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
        cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*
    Create a notification for this product.
    linuxfoundation yocto Affected: 4.0
        cpe:2.3:a:linuxfoundation:yocto:4.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T09:14:40.963Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://corp.mediatek.com/product-security-bulletin/August-2023"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt2713:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt2713",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt6879:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt6879",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt6895:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt6895",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt6983:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt6983",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8188:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8188",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8195:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8195",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8395:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8395",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8673:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8673",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*",
                  "cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "android",
                "vendor": "google",
                "versions": [
                  {
                    "status": "affected",
                    "version": "12.0"
                  },
                  {
                    "status": "affected",
                    "version": "13.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:linuxfoundation:yocto:4.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "yocto",
                "vendor": "linuxfoundation",
                "versions": [
                  {
                    "status": "affected",
                    "version": "4.0"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "LOCAL",
                  "availabilityImpact": "HIGH",
                  "baseScore": 6.7,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "HIGH",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-20805",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-22T14:59:23.445486Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-787",
                    "description": "CWE-787 Out-of-bounds Write",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-22T15:13:53.163Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "MT2713, MT6879, MT6895, MT6983, MT8188, MT8195, MT8395, MT8673",
              "vendor": "MediaTek, Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "Android 12.0, 13.0 / IOT-v23.0 (Yocto 4.0)"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07199773; Issue ID: ALPS07326411."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Elevation of Privilege",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-08-07T03:21:48.680Z",
            "orgId": "ee979b05-11f8-4f25-a7e0-a1fa9c190374",
            "shortName": "MediaTek"
          },
          "references": [
            {
              "url": "https://corp.mediatek.com/product-security-bulletin/August-2023"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ee979b05-11f8-4f25-a7e0-a1fa9c190374",
        "assignerShortName": "MediaTek",
        "cveId": "CVE-2023-20805",
        "datePublished": "2023-08-07T03:21:48.680Z",
        "dateReserved": "2022-10-28T02:03:23.671Z",
        "dateUpdated": "2024-10-22T15:13:53.163Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-20804 (GCVE-0-2023-20804)

    Vulnerability from cvelistv5 – Published: 2023-08-07 03:21 – Updated: 2024-10-22 15:14
    VLAI
    Summary
    In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07199773; Issue ID: ALPS07326384.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-22 14:59 UTC
    CWE
    • Elevation of Privilege
    • CWE-787 - Out-of-bounds Write
    Impacted products
    Vendor Product Version
    MediaTek, Inc. MT2713, MT6879, MT6895, MT6983, MT8188, MT8195, MT8395, MT8673 Affected: Android 12.0, 13.0 / IOT-v23.0 (Yocto 4.0)
    Create a notification for this product.
    mediatek mt2713 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt2713:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt6879 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt6879:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt6895 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt6895:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt6983 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt6983:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8188 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8188:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8195 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8195:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8395 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8395:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8673 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8673:-:*:*:*:*:*:*:*
    Create a notification for this product.
    google android Affected: 12.0
    Affected: 13.0
        cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
        cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*
    Create a notification for this product.
    linuxfoundation yocto Affected: 4.0
        cpe:2.3:a:linuxfoundation:yocto:4.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T09:14:40.978Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://corp.mediatek.com/product-security-bulletin/August-2023"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt2713:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt2713",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt6879:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt6879",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt6895:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt6895",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt6983:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt6983",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8188:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8188",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8195:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8195",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8395:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8395",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8673:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8673",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*",
                  "cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "android",
                "vendor": "google",
                "versions": [
                  {
                    "status": "affected",
                    "version": "12.0"
                  },
                  {
                    "status": "affected",
                    "version": "13.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:linuxfoundation:yocto:4.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "yocto",
                "vendor": "linuxfoundation",
                "versions": [
                  {
                    "status": "affected",
                    "version": "4.0"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "LOCAL",
                  "availabilityImpact": "HIGH",
                  "baseScore": 6.7,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "HIGH",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-20804",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-22T14:59:35.581255Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-787",
                    "description": "CWE-787 Out-of-bounds Write",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-22T15:14:08.297Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "MT2713, MT6879, MT6895, MT6983, MT8188, MT8195, MT8395, MT8673",
              "vendor": "MediaTek, Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "Android 12.0, 13.0 / IOT-v23.0 (Yocto 4.0)"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07199773; Issue ID: ALPS07326384."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Elevation of Privilege",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-08-07T03:21:46.656Z",
            "orgId": "ee979b05-11f8-4f25-a7e0-a1fa9c190374",
            "shortName": "MediaTek"
          },
          "references": [
            {
              "url": "https://corp.mediatek.com/product-security-bulletin/August-2023"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ee979b05-11f8-4f25-a7e0-a1fa9c190374",
        "assignerShortName": "MediaTek",
        "cveId": "CVE-2023-20804",
        "datePublished": "2023-08-07T03:21:46.656Z",
        "dateReserved": "2022-10-28T02:03:23.671Z",
        "dateUpdated": "2024-10-22T15:14:08.297Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-20803 (GCVE-0-2023-20803)

    Vulnerability from cvelistv5 – Published: 2023-08-07 03:21 – Updated: 2024-10-22 15:14
    VLAI
    Summary
    In imgsys, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07326455; Issue ID: ALPS07326374.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-22 14:59 UTC
    CWE
    • Elevation of Privilege
    • CWE-787 - Out-of-bounds Write
    Impacted products
    Vendor Product Version
    MediaTek, Inc. MT2713, MT6879, MT6895, MT6983, MT8188, MT8195, MT8395, MT8673 Affected: Android 12.0, 13.0 / IOT-v23.0 (Yocto 4.0)
    Create a notification for this product.
    mediatek mt2713 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt2713:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt6879 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt6879:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt6895 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt6895:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt6983 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt6983:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8188 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8188:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8195 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8195:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8395 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8395:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8673 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8673:-:*:*:*:*:*:*:*
    Create a notification for this product.
    google android Affected: 12.0
    Affected: 13.0
        cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
        cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*
    Create a notification for this product.
    linuxfoundation yocto Affected: 4.0
        cpe:2.3:a:linuxfoundation:yocto:4.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T09:14:40.970Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://corp.mediatek.com/product-security-bulletin/August-2023"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt2713:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt2713",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt6879:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt6879",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt6895:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt6895",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt6983:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt6983",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8188:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8188",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8195:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8195",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8395:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8395",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8673:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8673",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*",
                  "cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "android",
                "vendor": "google",
                "versions": [
                  {
                    "status": "affected",
                    "version": "12.0"
                  },
                  {
                    "status": "affected",
                    "version": "13.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:linuxfoundation:yocto:4.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "yocto",
                "vendor": "linuxfoundation",
                "versions": [
                  {
                    "status": "affected",
                    "version": "4.0"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "LOCAL",
                  "availabilityImpact": "HIGH",
                  "baseScore": 6.7,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "HIGH",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-20803",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-22T14:59:45.539222Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-787",
                    "description": "CWE-787 Out-of-bounds Write",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-22T15:14:20.728Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "MT2713, MT6879, MT6895, MT6983, MT8188, MT8195, MT8395, MT8673",
              "vendor": "MediaTek, Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "Android 12.0, 13.0 / IOT-v23.0 (Yocto 4.0)"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In imgsys, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07326455; Issue ID: ALPS07326374."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Elevation of Privilege",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-08-07T03:21:44.390Z",
            "orgId": "ee979b05-11f8-4f25-a7e0-a1fa9c190374",
            "shortName": "MediaTek"
          },
          "references": [
            {
              "url": "https://corp.mediatek.com/product-security-bulletin/August-2023"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ee979b05-11f8-4f25-a7e0-a1fa9c190374",
        "assignerShortName": "MediaTek",
        "cveId": "CVE-2023-20803",
        "datePublished": "2023-08-07T03:21:44.390Z",
        "dateReserved": "2022-10-28T02:03:23.671Z",
        "dateUpdated": "2024-10-22T15:14:20.728Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-20677 (GCVE-0-2023-20677)

    Vulnerability from cvelistv5 – Published: 2023-04-06 00:00 – Updated: 2024-10-23 14:21
    VLAI
    Summary
    In wlan, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07588413; Issue ID: ALPS07588436.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-23 13:09 UTC
    CWE
    • Information Disclosure
    • CWE-125 - Out-of-bounds Read
    Impacted products
    Vendor Product Version
    MediaTek, Inc. MT5221, MT6781, MT6789, MT6833, MT6855, MT6877, MT6879, MT6895, MT6983, MT7663, MT7668, MT7902, MT7921, MT8167S, MT8168, MT8169, MT8175, MT8185, MT8362A, MT8365, MT8385, MT8518, MT8532, MT8675, MT8695, MT8766, MT8768, MT8771, MT8781, MT8786, MT8788, MT8789, MT8791T, MT8797, MT8798 Affected: Android 11.0, 12.0, 13.0 / Yocto 3.1, 3.3, 4.0 / Linux-4.19 (for MT5221, MT7663, MT7668, MT7902 and MT7921 chipsets only)
    Create a notification for this product.
    mediatek mt5221 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt5221:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt6781 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt6781:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt6789 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt6789:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt6833 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt6833:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt6855 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt6855:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt6877 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt6877:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt6879 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt6879:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt6895 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt6895:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt6983 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt6983:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt7663 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt7663:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt7668 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt7668:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt7902 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt7902:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt7921 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt7921:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8167s Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8167s:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8168 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8168:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8169 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8169:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8175 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8175:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8185 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8185:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8362a Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8362a:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8365 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8365:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8385 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8385:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8518 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8518:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8532 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8532:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8675 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8675:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8695 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8695:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8766 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8766:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8768 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8768:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8771 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8771:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8781 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8781:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8786 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8786:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8788 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8788:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8789 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8789:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8791t Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8791t:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8797 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8797:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8798 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8798:-:*:*:*:*:*:*:*
    Create a notification for this product.
    google android Affected: 11.0
    Affected: 12.0
    Affected: 13.0
        cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:*
        cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
        cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*
    Create a notification for this product.
    linuxfoundation yocto Affected: 3.1
    Affected: 3.3
    Affected: 4.0
        cpe:2.3:a:linuxfoundation:yocto:3.1:*:*:*:*:*:*:*
        cpe:2.3:a:linuxfoundation:yocto:3.3:*:*:*:*:*:*:*
        cpe:2.3:a:linuxfoundation:yocto:4.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T09:14:39.893Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://corp.mediatek.com/product-security-bulletin/April-2023"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt5221:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt5221",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt6781:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt6781",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt6789:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt6789",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt6833:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt6833",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt6855:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt6855",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt6877:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt6877",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt6879:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt6879",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt6895:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt6895",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt6983:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt6983",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt7663:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt7663",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt7668:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt7668",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt7902:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt7902",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt7921:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt7921",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8167s:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8167s",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8168:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8168",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8169:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8169",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8175:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8175",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8185:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8185",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8362a:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8362a",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8365:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8365",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8385:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8385",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8518:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8518",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8532:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8532",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8675:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8675",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8695:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8695",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8766:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8766",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8768:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8768",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8771:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8771",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8781:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8781",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8786:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8786",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8788:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8788",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8789:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8789",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8791t:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8791t",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8797:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8797",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8798:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8798",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:*",
                  "cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*",
                  "cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "android",
                "vendor": "google",
                "versions": [
                  {
                    "status": "affected",
                    "version": "11.0"
                  },
                  {
                    "status": "affected",
                    "version": "12.0"
                  },
                  {
                    "status": "affected",
                    "version": "13.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:linuxfoundation:yocto:3.1:*:*:*:*:*:*:*",
                  "cpe:2.3:a:linuxfoundation:yocto:3.3:*:*:*:*:*:*:*",
                  "cpe:2.3:a:linuxfoundation:yocto:4.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "yocto",
                "vendor": "linuxfoundation",
                "versions": [
                  {
                    "status": "affected",
                    "version": "3.1"
                  },
                  {
                    "status": "affected",
                    "version": "3.3"
                  },
                  {
                    "status": "affected",
                    "version": "4.0"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "LOCAL",
                  "availabilityImpact": "NONE",
                  "baseScore": 4.4,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "HIGH",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-20677",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-23T13:09:16.177110Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-125",
                    "description": "CWE-125 Out-of-bounds Read",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-23T14:21:59.661Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "MT5221, MT6781, MT6789, MT6833, MT6855, MT6877, MT6879, MT6895, MT6983, MT7663, MT7668, MT7902, MT7921, MT8167S, MT8168, MT8169, MT8175, MT8185, MT8362A, MT8365, MT8385, MT8518, MT8532, MT8675, MT8695, MT8766, MT8768, MT8771, MT8781, MT8786, MT8788, MT8789, MT8791T, MT8797, MT8798",
              "vendor": "MediaTek, Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "Android 11.0, 12.0, 13.0 / Yocto 3.1, 3.3, 4.0 / Linux-4.19 (for MT5221, MT7663, MT7668, MT7902 and MT7921 chipsets only)"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In wlan, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07588413; Issue ID: ALPS07588436."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Information Disclosure",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-04-06T00:00:00.000Z",
            "orgId": "ee979b05-11f8-4f25-a7e0-a1fa9c190374",
            "shortName": "MediaTek"
          },
          "references": [
            {
              "url": "https://corp.mediatek.com/product-security-bulletin/April-2023"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ee979b05-11f8-4f25-a7e0-a1fa9c190374",
        "assignerShortName": "MediaTek",
        "cveId": "CVE-2023-20677",
        "datePublished": "2023-04-06T00:00:00.000Z",
        "dateReserved": "2022-10-28T00:00:00.000Z",
        "dateUpdated": "2024-10-23T14:21:59.661Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }