CVE-2022-40674 PUBLISHED CVSS 7.5 HIGH

Local users can write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This can lead to local privilege escalation to root. This occurs because an attacker can repeat a keyword, which is mishandled because arithmetic ADD is used instead of bitwise OR.

EPSS 1.09% · 77.8th percentile

Risk Scores

CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:W/RC:C
EPSS Score
1.09%
77.8th percentile

Affected Products

VendorProductVersions
ABBABB M2M Gateway ARM600, firmware versions >=4.1.2|<=5.0.3
ABBABB M2M Gateway SW, software versions >=5.0.1|<=5.0.3

Timeline

References

Open in Interactive Console →