7.8
CVE-2023-39902
- EPSS 0.1%
- Veröffentlicht 17.10.2023 12:15:09
- Zuletzt bearbeitet 21.11.2024 08:16:00
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
A software vulnerability has been identified in the U-Boot Secondary Program Loader (SPL) before 2023.07 on select NXP i.MX 8M family processors. Under certain conditions, a crafted Flattened Image Tree (FIT) format structure can be used to overwrite SPL memory, allowing unauthenticated software to execute on the target, leading to privilege escalation. This affects i.MX 8M, i.MX 8M Mini, i.MX 8M Nano, and i.MX 8M Plus.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Nxp ≫ Uboot Secondary Program Loader Version < 2023.07
Nxp ≫ I.Mx 8m Version-
Nxp ≫ I.Mx 8m Mini Version-
Nxp ≫ I.Mx 8m Nano Version-
Nxp ≫ I.Mx 8m Plus Version-
Nxp ≫ I.Mx 8m Mini Version-
Nxp ≫ I.Mx 8m Nano Version-
Nxp ≫ I.Mx 8m Plus Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.1% | 0.282 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
cve@mitre.org | 7 | 1 | 5.9 |
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-281 Improper Preservation of Permissions
The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.