2023-07-27 23:55:28 +00:00
{
"id" : "CVE-2022-43701" ,
"sourceIdentifier" : "arm-security@arm.com" ,
"published" : "2023-07-27T22:15:10.077" ,
2023-08-07 20:00:39 +00:00
"lastModified" : "2023-08-07T19:34:09.343" ,
"vulnStatus" : "Analyzed" ,
2023-07-27 23:55:28 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "When the installation directory does not have sufficiently restrictive file permissions, an attacker can modify files in the installation directory to cause execution of malicious code.\n\n"
}
] ,
2023-08-07 20:00:39 +00:00
"metrics" : {
"cvssMetricV31" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" ,
"attackVector" : "LOCAL" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
"availabilityImpact" : "HIGH" ,
"baseScore" : 7.8 ,
"baseSeverity" : "HIGH"
} ,
"exploitabilityScore" : 1.8 ,
"impactScore" : 5.9
}
]
} ,
2023-07-27 23:55:28 +00:00
"weaknesses" : [
2023-08-07 20:00:39 +00:00
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-276"
}
]
} ,
2023-07-27 23:55:28 +00:00
{
"source" : "arm-security@arm.com" ,
"type" : "Secondary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-276"
}
]
}
] ,
2023-08-07 20:00:39 +00:00
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:arm:arm_compiler:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "5.00" ,
"versionEndIncluding" : "5.06" ,
"matchCriteriaId" : "BA7346D6-D534-4BE5-A743-299C0D492C5A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:arm:arm_compiler:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "6.00" ,
"versionEndExcluding" : "6.20" ,
"matchCriteriaId" : "51BDDDC3-A2E2-47E3-A161-DD2396647D55"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:arm:arm_compiler_for_embedded_fusa:6.16:*:*:*:lts:*:*:*" ,
"matchCriteriaId" : "27EF772A-BF7D-487A-9B34-6521220068F0"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:arm:arm_compiler_for_functional_safety:6.6:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E56C6F5A-5EA7-42F8-958D-9B02944C57BB"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:arm:arm_development_studio:*:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "241064F9-9B76-41FA-A8B5-4FBCDE51BAD2"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:arm:arm_mobile_studio:*:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "7379BFFC-68B0-4949-AA50-183E6E95D081"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:arm:ds_development_studio:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "5.0.0" ,
"versionEndIncluding" : "5.29.3" ,
"matchCriteriaId" : "30B049E4-59A7-47D8-A491-D947C4AAD4AC"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:arm:fast_models:*:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "402695FC-FB49-4279-ADDD-1DD6F7B6D19B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:arm:gnu_toolchain:*:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "4CB32D37-1918-4C3F-9766-2FA8230E179E"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:arm:keil_mdk:*:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "9EA7E513-39DF-4DE9-B73D-A38221714005"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:arm:linaro_forge:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "22.1" ,
"matchCriteriaId" : "66DD3005-2E38-470A-B57B-5544133F7D7E"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:arm:mbed_studio:*:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "7F6DB3D5-82E1-428D-8E16-B1676B3D7D51"
}
]
}
]
}
] ,
2023-07-27 23:55:28 +00:00
"references" : [
{
"url" : "https://developer.arm.com/documentation/ka005596/latest" ,
2023-08-07 20:00:39 +00:00
"source" : "arm-security@arm.com" ,
"tags" : [
"Vendor Advisory"
]
2023-07-27 23:55:28 +00:00
}
]
}