A command injection vulnerability exists in the IOCTL that manages OTA updates. A specially crafted command can lead to command execution as the root user. An attacker can make authenticated requests to trigger this vulnerability.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: Bitdefender
Published: 2024-05-15T12:07:44.554Z
Updated: 2024-08-02T08:28:21.329Z
Reserved: 2023-11-27T14:22:33.541Z
Link: CVE-2023-6321
Vulnrichment
Updated: 2024-08-02T08:28:21.329Z
NVD
Status : Awaiting Analysis
Published: 2024-05-15T13:15:25.230
Modified: 2024-11-21T08:43:37.223
Link: CVE-2023-6321
Redhat
No data.