CVE-2023-45841
CVSS 3.1 Score 8.1 of 10 (high)
Details
Published Dec 5, 2023
Updated: Dec 12, 2023
CWE ID 494
Summary
CVE-2023-45841 is a data integrity vulnerability affecting the package hash checking functionality in Buildroot 2023.08.1 and commit 622698d7847. A man-in-the-middle attacker can exploit this issue, resulting in arbitrary command execution within the builder. The vulnerability specifically targets the `versal-firmware` package. This weakness could allow an attacker to introduce malicious code into the build process, potentially compromising the entire system. Users are strongly advised to upgrade to a patched version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share