// For flags

CVE-2022-43702

Incomplete verification of installation file signature

Severity Score

7.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

When the directory containing the installer does not have sufficiently restrictive file permissions, an attacker can modify (or replace) the installer to execute malicious code.

*Credits: FalconCorruption, Intel
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-10-24 CVE Reserved
  • 2023-07-27 CVE Published
  • 2023-08-08 EPSS Updated
  • 2024-08-03 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-276: Incorrect Default Permissions
  • CWE-284: Improper Access Control
CAPEC
  • CAPEC-233: Privilege Escalation
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Arm
Search vendor "Arm"
Arm Compiler
Search vendor "Arm" for product "Arm Compiler"
>= 5.00 <= 5.06
Search vendor "Arm" for product "Arm Compiler" and version " >= 5.00 <= 5.06"
-
Affected
Arm
Search vendor "Arm"
Arm Compiler
Search vendor "Arm" for product "Arm Compiler"
>= 6.00 < 6.18
Search vendor "Arm" for product "Arm Compiler" and version " >= 6.00 < 6.18"
-
Affected
Arm
Search vendor "Arm"
Arm Compiler For Embedded Fusa
Search vendor "Arm" for product "Arm Compiler For Embedded Fusa"
6.16
Search vendor "Arm" for product "Arm Compiler For Embedded Fusa" and version "6.16"
lts
Affected
Arm
Search vendor "Arm"
Arm Compiler For Functional Safety
Search vendor "Arm" for product "Arm Compiler For Functional Safety"
>= 6.6 < 6.6.5
Search vendor "Arm" for product "Arm Compiler For Functional Safety" and version " >= 6.6 < 6.6.5"
-
Affected
Arm
Search vendor "Arm"
Arm Development Studio
Search vendor "Arm" for product "Arm Development Studio"
*-
Affected
Arm
Search vendor "Arm"
Ds Development Studio
Search vendor "Arm" for product "Ds Development Studio"
>= 5.0.0 <= 5.29.3
Search vendor "Arm" for product "Ds Development Studio" and version " >= 5.0.0 <= 5.29.3"
-
Affected
Arm
Search vendor "Arm"
Fast Models
Search vendor "Arm" for product "Fast Models"
*-
Affected