When the directory containing the installer does not have sufficiently restrictive file permissions, an attacker can modify (or replace) the installer to execute malicious code.
References
Configurations
Configuration 1 (hide)
|
History
13 Feb 2025, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://developer.arm.com/documentation/ka005596/latest - Vendor Advisory | |
| Summary | When the directory containing the installer does not have sufficiently restrictive file permissions, an attacker can modify (or replace) the installer to execute malicious code. |
13 Feb 2024, 20:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
07 Aug 2023, 19:34
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-276 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
| First Time |
Arm
Arm arm Development Studio Arm arm Compiler For Embedded Fusa Arm fast Models Arm arm Compiler For Functional Safety Arm arm Compiler Arm ds Development Studio |
|
| CPE | cpe:2.3:a:arm:arm_development_studio:*:*:*:*:*:*:*:* cpe:2.3:a:arm:ds_development_studio:*:*:*:*:*:*:*:* cpe:2.3:a:arm:arm_compiler_for_embedded_fusa:6.16:*:*:*:lts:*:*:* cpe:2.3:a:arm:arm_compiler:*:*:*:*:*:*:*:* cpe:2.3:a:arm:fast_models:*:*:*:*:*:*:*:* cpe:2.3:a:arm:arm_compiler_for_functional_safety:*:*:*:*:*:*:*:* |
|
| References | (MISC) https://developer.arm.com/documentation/ka005596/latest - Vendor Advisory |
27 Jul 2023, 22:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2023-07-27 22:15
Updated : 2025-02-13 17:15
NVD link : CVE-2022-43702
Mitre link : CVE-2022-43702
JSON object : View
Products Affected
arm
- arm_compiler_for_embedded_fusa
- fast_models
- arm_development_studio
- arm_compiler_for_functional_safety
- ds_development_studio
- arm_compiler
CWE
CWE-276
Incorrect Default Permissions
