CVE-2023-45593
A CWE-184 “Incomplete List of Disallowed Inputs” vulnerability in the embedded Chromium browser (concerning the handling of alternative URLs, other than “http://localhost”) allows a physical attacker to read arbitrary files on the file system, alter the configuration of the embedded browser, and have other unspecified impacts to the confidentiality, integrity, and availability of the device.
A physical unauthenticated attacker may access sensitive resources on the device, alter the device configuration, or, in the worst-case, achieve root Remote Code Execution.
March 4, 2024
This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2.
CVE-2023-45593
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
6.8
Update to imx6 bundle version imx6_1.0.7-2.
Andrea Palanca of Nozomi Networks
Nozomi Networks Labs curates threat and vulnerability insights that are continuously fed into the Nozomi Networks platform to ensure our sensors can detect existing and emerging threats and vulnerabilities that threaten customers environments.
Learn more

