First published: Thu Apr 13 2023(Updated: )
Dmidecode before 3.5 allows -dump-bin to overwrite a local file. This has security relevance because, for example, execution of Dmidecode via Sudo is plausible.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nongnu Dmidecode | <3.5 | |
IBM Security Verify Governance, Identity Manager software component | <=ISVG 10.0.2 | |
IBM Security Verify Governance, Identity Manager virtual appliance component | <=ISVG 10.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-30630 has not been explicitly rated, but it poses a risk due to its potential to overwrite local files.
To fix CVE-2023-30630, upgrade Dmidecode to version 3.5 or later.
CVE-2023-30630 affects Dmidecode versions prior to 3.5 and IBM Security Verify Governance components up to ISVG 10.0.2.
The impact of CVE-2023-30630 includes the risk of local file overwrites, which could lead to privilege escalation or data loss.
Yes, CVE-2023-30630 is exploitable when Dmidecode is executed with elevated privileges, such as via Sudo.