CVE-2022-43702: Incomplete verification of installation file signature
When the directory containing the installer does not have sufficiently restrictive file permissions, an attacker can modify (or replace) the installer to execute malicious code.
Affected Software
Event History
Frequently Asked Questions
What is vulnerability CVE-2022-43702?
Vulnerability CVE-2022-43702 occurs when the directory containing the installer has insufficient file permissions, allowing an attacker to modify or replace the installer to execute malicious code.
What is the severity level of CVE-2022-43702?
The severity level of CVE-2022-43702 is high, with a CVSS score of 7.8.
Which software packages are affected by CVE-2022-43702?
The affected software packages include Arm Arm Compiler (versions 5.00 to 5.06 and versions 6.00 to 6.18), Arm Arm Compiler for Embedded Fusa (version 6.16), Arm Arm Compiler for Functional Safety (versions 6.6 to 6.6.5), Arm Arm Development Studio, Arm DS Development Studio (versions 5.0.0 to 5.29.3), and Arm Fast Models.
How can I fix CVE-2022-43702?
To fix CVE-2022-43702, ensure that the directory containing the installer has appropriate file permissions that prevent unauthorized modification or replacement of the installer.
Where can I find more information about CVE-2022-43702?
More information about vulnerability CVE-2022-43702 can be found at: https://developer.arm.com/documentation/ka005596/latest