2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2022-27152" ,
"sourceIdentifier" : "cve@mitre.org" ,
"published" : "2022-04-08T18:15:09.987" ,
2023-08-29 23:55:28 +00:00
"lastModified" : "2023-08-29T22:15:08.747" ,
"vulnStatus" : "Modified" ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "Roku devices running RokuOS v9.4.0 build 4200 or earlier that uses a Realtek WiFi chip is vulnerable to Arbitrary file modification."
} ,
{
"lang" : "es" ,
"value" : "Los dispositivos Roku que ejecutan RokuOS versi\u00f3n v9.4.0 build 4200 o anteriores, que usan un chip WiFi de Realtek son vulnerables a una modificaci\u00f3n arbitraria de archivos"
}
] ,
"metrics" : {
"cvssMetricV31" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" ,
"attackVector" : "ADJACENT_NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "HIGH" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 5.7 ,
"baseSeverity" : "MEDIUM"
} ,
"exploitabilityScore" : 2.1 ,
"impactScore" : 3.6
}
] ,
"cvssMetricV2" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "2.0" ,
"vectorString" : "AV:A/AC:L/Au:S/C:N/I:P/A:N" ,
"accessVector" : "ADJACENT_NETWORK" ,
"accessComplexity" : "LOW" ,
"authentication" : "SINGLE" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "PARTIAL" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 2.7
} ,
"baseSeverity" : "LOW" ,
"exploitabilityScore" : 5.1 ,
"impactScore" : 2.9 ,
"acInsufInfo" : false ,
"obtainAllPrivilege" : false ,
"obtainUserPrivilege" : false ,
"obtainOtherPrivilege" : false ,
"userInteractionRequired" : false
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "NVD-CWE-noinfo"
}
]
}
] ,
"configurations" : [
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:roku:roku_os:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "9.4.0" ,
"matchCriteriaId" : "DD2C3EBF-6FC5-4EBC-99D3-40E454B6606D"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:roku:express:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "0FF33B1E-AD75-46CB-9AAD-E762D7B2994D"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:roku:express_4k\\+:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "32F49C9D-7042-473E-88A7-6121513E92C0"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:roku:roku_tv:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E683FFF5-6B1F-4847-9B50-9C17880870D2"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:roku:streambar:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "50520608-A2C8-4D08-971A-D608469904D3"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:roku:streambar_pro:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "B7F65E30-6D07-48E7-80DD-E8275443480C"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:roku:streaming_stick_4k:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "BF338F83-6265-4774-9D0A-0F3448695179"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:roku:streaming_stick_4k\\+:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "57C736A0-122E-4445-8BF2-DA4EC0822575"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:roku:ultra:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "98F084EC-AB6A-4488-A6F2-9EAF50281F73"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:roku:wireless_speakers:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8B95508E-9223-478B-A6A9-87E655DD5354"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:roku:wireless_subwoofer:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "9A4066B4-DDE3-4937-8B51-7DEFBF3B7D02"
}
]
}
]
}
] ,
"references" : [
{
"url" : "https://github.com/llamasoft/RootMyRoku" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Third Party Advisory"
]
2023-08-29 23:55:28 +00:00
} ,
{
"url" : "https://support.roku.com/article/12554388937879" ,
"source" : "cve@mitre.org"
2023-04-24 12:24:31 +02:00
}
]
}