CVE-2023-45841

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
05/12/2023
Last modified:
04/11/2025

Description

Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary command execution in the builder.This vulnerability is related to the `versal-firmware` package.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:buildroot:buildroot:2023.08.1:*:*:*:*:*:*:*