CVE-2023-32855: Medium severity yocto project vulnerability
In aee, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07909204; Issue ID: ALPS07909204.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-32855?
CVE-2023-32855 is a vulnerability in aee that allows for escalation of privilege due to a missing permission check.
How severe is CVE-2023-32855?
CVE-2023-32855 has a severity score of 6.7 out of 10, which is considered medium severity.
Which software versions are affected by CVE-2023-32855?
CVE-2023-32855 affects the following software versions: Linuxfoundation Yocto 2.6, Linuxfoundation Yocto 3.3, Linuxfoundation Yocto 4.0, Rdkcentral Rdk-b 2022q3, Google Android 12.0, Google Android 13.0, Openwrt Openwrt 19.07.0, Openwrt Openwrt 21.02.
Is user interaction required for exploitation of CVE-2023-32855?
No, user interaction is not needed for exploitation of CVE-2023-32855.
How can I fix CVE-2023-32855?
To fix CVE-2023-32855, apply the provided patch with Patch ID ALPS07909204 or update to a non-vulnerable version.