VDB

CVE-2022-40674

CVE-2022-40674 PUBLISHED CVSS 7.5 HIGH

Local users can write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This can lead to local privilege escalation to root. This occurs because an attacker can repeat a keyword, which is mishandled because arithmetic ADD is used instead of bitwise OR.

EPSS 2.21% · 81.9th percentile

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:W/RC:C
EPSS Score
2.21%
81.9th percentile

Affected Products

VendorProductVersions
ABBABB M2M Gateway ARM600, firmware versions >=4.1.2|<=5.0.3
ABBABB M2M Gateway SW, software versions >=5.0.1|<=5.0.3

Timeline

  • Sep 14, 2022 CVE Published
  • Sep 14, 2022 EPSS Score
  • Oct 29, 2022 EPSS Score
  • Dec 14, 2022 EPSS Score
  • Jan 28, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Mar 15, 2023 EPSS Score
  • Jun 13, 2023 EPSS Score
  • Jul 29, 2023 EPSS Score
  • Sep 12, 2023 EPSS Score
  • Oct 28, 2023 EPSS Score
  • Jan 27, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›