VDB
CVE-2020-25860
CVE-2020-25860
PUBLISHED
CVSS 6.599999904632568 MEDIUM
The install.c module in the Pengutronix RAUC update client prior to version 1.5 has a Time-of-Check Time-of-Use vulnerability, where signature verification on an update file takes place before the file is reopened for installation. An attacker who can modify the update file just before it is reopened can install arbitrary code on the device.
EPSS 1.42% · 70.9th percentile
Risk Scores
CVSS 3.1
6.599999904632568
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS Score
1.42%
70.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:22.04:LTS | rauc | 0, 1.5.1-1build1, 1.6-1 |
| Ubuntu:20.04:LTS | rauc | 0, 1.1-2, 1.2-1 |
Timeline
- Dec 21, 2020 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 28, 2021 EPSS Score
- Feb 4, 2022 EPSS Score
- Mar 1, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Jul 4, 2022 EPSS Score
- Sep 6, 2022 EPSS Score
- Nov 8, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
References
- https://ubuntu.com/security/CVE-2020-25860 third-party-advisory
- https://github.com/rauc/rauc/security/advisories/GHSA-cgf3-h62j-w9vv third-party-advisory
- https://www.vdoo.com/blog/cve-2020-25860-significant-vulnerability-discovered-rauc-embedded-firmware-update-framework third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2020-25860 third-party-advisory