PT-2022-14307 · Preloader · Preloader

Published

2022-03-09

·

Updated

2023-08-08

·

CVE-2022-20060

CVSS v3.1

6.6

Medium

VectorAV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions preloader (usb) (affected versions not specified)
Description The issue is related to a missing proper image authentication in the preloader, which could lead to a permission bypass. This might result in a local escalation of privilege for an attacker with physical access to the device. No additional execution privileges are needed, but user interaction is required for exploitation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2022-20060

Affected Products

Preloader