VDB
CVE-2023-32855
CVE-2023-32855
PUBLISHED
CVSS 6.699999809265137 MEDIUM
In aee, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07909204; Issue ID: ALPS07909204.
EPSS 0.11% · 1.3th percentile
Risk Scores
CVSS 3.1
6.699999809265137
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.11%
1.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| rdkcentral | rdk-b | 2022q3, 2022q3 |
| linuxfoundation | yocto | 3.3, 2.6, 4.0 |
| android | 12.0, 13.0, 12.0 | |
| openwrt | openwrt | 21.02, 19.07.0, 21.02 |
| MediaTek, Inc. | MT2735, MT2737, MT6765, MT6768, MT6769, MT6833, MT6835, MT6853, MT6853T, MT6855, MT6873, MT6875, MT6877, MT6879, MT6880, MT6885, MT6889, MT6890, MT6893, MT6895, MT6980, MT6983, MT6985, MT6990, MT8667, MT8765, MT8768, MT8786, MT8791, MT8791T, MT8791WIFI, MT8798 | Android 12.0, 13.0 / OpenWrt 1907, 2102 / Yocto 2.6, 3.3, 4.0 / RDK-B 22Q3, Android 12.0, 13.0 / OpenWrt 1907, 2102 / Yocto 2.6, 3.3, 4.0 / RDK-B 22Q3 |
Timeline
- Dec 4, 2023 EPSS Score
- Dec 4, 2023 CVE Published
- Dec 22, 2023 PoC Published
- Jan 3, 2024 EPSS Score
- Feb 1, 2024 EPSS Score
- Mar 2, 2024 EPSS Score
- Mar 31, 2024 EPSS Score
- Apr 30, 2024 EPSS Score
- May 30, 2024 EPSS Score
- Jun 28, 2024 EPSS Score
- Jul 28, 2024 EPSS Score
- Aug 27, 2024 EPSS Score