CVE Vulnerabilities

CVE-2022-38453

Active Debug Code

Published: Sep 13, 2022 | Modified: Nov 21, 2024
CVSS 3.x
4.4
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Multiple binary application files on the CMS8000 device are compiled with not stripped and debug_info compilation settings. These compiler settings greatly decrease the level of effort for a threat actor to reverse engineer sensitive code and identify additional vulnerabilities.

Weakness

The product is released with debugging code still enabled or active.

Affected Software

Name Vendor Start Version End Version
Cms8000_firmware Contechealth - (including) - (including)

Potential Mitigations

References