CVE-2022-32293

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
03/08/2022
Last modified:
21/12/2023

Description

In ConnMan through 1.41, a man-in-the-middle attack against a WISPR HTTP query could be used to trigger a use-after-free in WISPR handling, leading to crashes or code execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:intel:connman:*:*:*:*:*:*:*:* 1.41 (including)
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*