CVE-2023-20821: Medium severity yocto project vulnerability
In nvram, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07937113; Issue ID: ALPS07937113.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-20821?
CVE-2023-20821 is a vulnerability in nvram that allows for a possible out of bounds write due to a missing bounds check, potentially leading to local escalation of privilege.
How severe is CVE-2023-20821?
CVE-2023-20821 has a severity rating of 6.7 out of 10, which is considered medium severity.
What software is affected by CVE-2023-20821?
The affected software includes Linuxfoundation Yocto 2.6, Rdkcentral Rdk-b 2022q3, Google Android 11.0, Google Android 12.0, Google Android 13.0, Openwrt Openwrt 19.07.0, and Openwrt Openwrt 21.02.0.
Is user interaction required to exploit CVE-2023-20821?
No, user interaction is not needed for exploitation of CVE-2023-20821.
How can CVE-2023-20821 be patched?
To patch CVE-2023-20821, apply the provided Patch ID: ALPS07937113 or Issue ID: ALPS07937113.