CVE-2022-0553Sensitive Information Exposure in Zephyr

Severity
4.6MEDIUMNVD
CNA6.5
EPSS
0.0%
top 86.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 11

Description

There is no check to see if slot 0 is being uploaded from the device to the host. When using encrypted images this means the unencrypted firmware can be retrieved easily.

CVSS vector

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 0.9 | Impact: 3.6

Affected Packages2 packages

CVEListV5zephyrproject-rtos/zephyrunspecifiedv3.0

Patches

🔴Vulnerability Details

1
CVEList
Possible to retrieve uncrypted firmware image2023-01-11
CVE-2022-0553 — Sensitive Information Exposure | cvebase