CVE-2022-43702

When the directory containing the installer does not have sufficiently restrictive file permissions, an attacker can modify (or replace) the installer to execute malicious code.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:arm:arm_compiler:*:*:*:*:*:*:*:*
cpe:2.3:a:arm:arm_compiler:*:*:*:*:*:*:*:*
cpe:2.3:a:arm:arm_compiler_for_embedded_fusa:6.16:*:*:*:lts:*:*:*
cpe:2.3:a:arm:arm_compiler_for_functional_safety:*:*:*:*:*:*:*:*
cpe:2.3:a:arm:arm_development_studio:*:*:*:*:*:*:*:*
cpe:2.3:a:arm:ds_development_studio:*:*:*:*:*:*:*:*
cpe:2.3:a:arm:fast_models:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-07-27 22:15

Updated : 2024-02-13 20:15


NVD link : CVE-2022-43702

Mitre link : CVE-2022-43702

CVE.ORG link : CVE-2022-43702


JSON object : View

Products Affected

arm

  • arm_compiler
  • ds_development_studio
  • arm_development_studio
  • fast_models
  • arm_compiler_for_embedded_fusa
  • arm_compiler_for_functional_safety
CWE
CWE-276

Incorrect Default Permissions

CWE-284

Improper Access Control