CVE Vulnerabilities

CVE-2022-40297

Improper Privilege Management

Published: Sep 09, 2022 | Modified: Apr 11, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

UBports Ubuntu Touch 16.04 allows the screen-unlock passcode to be used for a privileged shell via Sudo. This passcode is only four digits, far below typical length/complexity for a user accounts password. NOTE: a third party states The described attack cannot be executed as demonstrated.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Ubuntu_touch Ubports 16.04 (including) 16.04 (including)

Potential Mitigations

References