CVE-2023-5456
A CWE-798 “Use of Hard-coded Credentials” vulnerability in the MariaDB database of the web application allows a remote unauthenticated attacker to access the database service and all included data with the same privileges of the web application.
A remote unauthenticated attacker may arbitrarily manipulate the device configuration.
March 4, 2024
This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2.
CVE-2023-5456
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
8.1
Update to imx6 bundle version imx6_1.0.7-2.
Andrea Palanca of Nozomi Networks
Nozomi Networks Labs curates threat and vulnerability insights that are continuously fed into the Nozomi Networks platform to ensure our sensors can detect existing and emerging threats and vulnerabilities that threaten customers environments.
Learn more

