Severity
4.6MEDIUM
EPSS
0.0%
top 94.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 10
Latest updateMar 11
Description
Improper Protection of Alternate Path vulnerability in Setup wizard process prior to SMR Mar-2022 Release 1 allows physical attacker package installation before finishing Setup wizard.
CVSS vector
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 0.5 | Impact: 3.6
Affected Packages4 packages
🔴Vulnerability Details
2GHSA▶
GHSA-jjv8-4r6f-2mj4: Improper Protection of Alternate Path vulnerability in Setup wizard process prior to SMR Mar-2022 Release 1 allows physical attacker package installat↗2022-03-11
CVEList▶
CVE-2022-24932: Improper Protection of Alternate Path vulnerability in Setup wizard process prior to SMR Mar-2022 Release 1 allows physical attacker package installat↗2022-03-08