CVE-2022-23220: High severity usbview vulnerability
Published Jan 21, 2022
·Updated
USBView 2.1 before 2.2 allows some local users (e.g., ones logged in via SSH) to execute arbitrary code as root because certain Polkit settings (e.g., allowany=yes) for pkexec disable the authentication requirement. Code execution can, for example, use the --gtk-module option. This affects Ubuntu, Debian, and Gentoo.
Affected Software
5 affected componentsFixes available
debian/usbview
2.0-21-g6fe2f4f-2+deb10u12.0-21-g6fe2f4f-2+deb11u13.0-33.1-1
Usbview Project Usbview<2.2
Canonical Ubuntu Linux
Debian Debian Linux
Gentoo Linux
Remediation
Patch Available
Event History
Jan 21, 2022
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for USBView?
The vulnerability ID for USBView is CVE-2022-23220.
2
What is the severity of CVE-2022-23220?
The severity of CVE-2022-23220 is high with a CVSS score of 7.8.
3
Which software versions of USBView are affected by CVE-2022-23220?
USBView versions before 2.2 are affected by CVE-2022-23220.
4
How can local users exploit CVE-2022-23220?
Some local users (e.g., ones logged in via SSH) can exploit CVE-2022-23220 to execute arbitrary code as root.
5
Are Ubuntu, Debian, and Gentoo Linux vulnerable to CVE-2022-23220?
No, Ubuntu, Debian, and Gentoo Linux are not vulnerable to CVE-2022-23220.