VDB
CVE-2023-32233
CVE-2023-32233
PUBLISHED
CVSS 7.800000190734863 HIGH
In the Linux kernel through 6.3.1, a use-after-free in Netfilter nf_tables when processing batch requests can be abused to perform arbitrary read and write operations on kernel memory. This could lead to an unprivileged local user gaining root access.
EPSS 12.97% · 95.9th percentile
Risk Scores
CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:W/RC:C
EPSS Score
12.97%
95.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| ABB | ABB M2M Gateway SW, software versions >=5.0.1|<=5.0.3 | |
| ABB | ABB M2M Gateway ARM600, firmware versions >=4.1.2|<=5.0.3 |
Timeline
- May 8, 2023 CVE Published
- May 9, 2023 EPSS Score
- Jun 15, 2023 EPSS Score
- Jul 22, 2023 EPSS Score
- Aug 27, 2023 EPSS Score
- Nov 9, 2023 EPSS Score
- Dec 16, 2023 EPSS Score
- Jan 22, 2024 EPSS Score
- Feb 28, 2024 EPSS Score
- Apr 4, 2024 EPSS Score
- May 11, 2024 EPSS Score
- Jun 17, 2024 EPSS Score
References
- https://library.e.abb.com/public/0498e4c0babd46aa9243aedd6f99c375/ARM600_user_758861_ENk.pdf advisory
- https://search.abb.com/library/Download.aspx?DocumentID=2NGA002579&LanguageCode=en&DocumentPartId=pdf&Action=Launch advisory
- https://psirt.abb.com/csaf/2025/2nga002579.json advisory
- https://library.e.abb.com/public/ffab1a14a42646c6adee38fc3de61dad/Arctic_csdepl_758860_ENf.pdf advisory
- https://new.abb.com/service/electrification/life-cycle-management?pe_data=D42415F457244415145784545584371%7C29609824 advisory
- https://search.abb.com/library/Download.aspx?DocumentID=1MRS758860&LanguageCode=en&DocumentPartId=&Action=Launch advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-32233 advisory