CVE-2023-39810
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Aug 28, 2023
Updated: Sep 7, 2023
CWE ID 22
Summary
CVE-2023-39810 denotes a vulnerability in the CPIO command of Busybox v1.33.2. This issue permits attackers to perform a directory traversal, potentially enabling them to gain unauthorized access to sensitive files or execute arbitrary code within the affected system. Successful exploitation of this vulnerability can lead to significant security risks and system compromise. The CPIO command, a common utility in embedded Linux systems using Busybox, is the culprit in this case. Upgrading to a patched version of Busybox is recommended to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- BusyBox