Impact
The vulnerability is an improper access control flaw in the SitewiseCustomFunction component of the Lambda Function Handler within nxp-auto-goldvip gvip. Attackers can exploit the misconfigured IAM permissions to invoke or modify the Lambda function remotely, potentially exposing or altering data that the function processes. This grants unauthorized users a level of privilege that should otherwise be protected.
Affected Systems
The flaw impacts nxp-auto-goldvip gvip versions up to 1.4.0, as documented in the project's release history. An upgrade to version 1.15.0 applies the corrected IAM permissions and deprecates older, vulnerable releases, thereby restoring proper access controls.
Risk and Exploitability
The CVSS score of 5.1 places this issue in the moderate severity range, and although EPSS data is not available, the description indicates the attack can be launched remotely, signifying a realistic exploitation potential. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed widespread exploitation, but the underlying access control weakness remains a concern for organizations that rely on this Lambda function.
OpenCVE Enrichment