VDB

CVE-2022-40674

CVE-2022-40674 PUBLISHED CVSS 7.5 HIGH

Local users can write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This can lead to local privilege escalation to root. This occurs because an attacker can repeat a keyword, which is mishandled because arithmetic ADD is used instead of bitwise OR.

EPSS 0.94% · 76.6th percentile

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:W/RC:C
EPSS Score
0.94%
76.6th percentile

Affected Products

VendorProductVersions
ABBABB M2M Gateway ARM600, firmware versions >=4.1.2|<=5.0.3
ABBABB M2M Gateway SW, software versions >=5.0.1|<=5.0.3

Exploit Intelligence

Timeline

  • Sep 14, 2022 CVE Published
  • Sep 14, 2022 EPSS Score
  • Oct 29, 2022 EPSS Score
  • Dec 13, 2022 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Mar 13, 2023 EPSS Score
  • Apr 27, 2023 EPSS Score
  • Jun 11, 2023 EPSS Score
  • Jul 26, 2023 EPSS Score
  • Oct 24, 2023 EPSS Score
  • Dec 8, 2023 EPSS Score
  • Jan 22, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›