A CWE-184 “Incomplete List of Disallowed Inputs” vulnerability in the embedded Chromium browser (concerning the handling of alternative URLs, other than “ http://localhost” ) allows a physical attacker to read arbitrary files on the file system, alter the configuration of the embedded browser, and have other unspecified impacts to the confidentiality, integrity, and availability of the device. This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2.
References
Link | Resource |
---|---|
https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2023-45593 | Third Party Advisory |
https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2023-45593 | Third Party Advisory |
Configurations
History
10 Apr 2025, 20:24
Type | Values Removed | Values Added |
---|---|---|
First Time |
Ailux imx6
Ailux |
|
CPE | cpe:2.3:a:ailux:imx6:*:*:*:*:*:*:*:* | |
References | () https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2023-45593 - Third Party Advisory | |
CWE | NVD-CWE-noinfo |
Information
Published : 2024-03-05 12:15
Updated : 2025-04-10 20:24
NVD link : CVE-2023-45593
Mitre link : CVE-2023-45593
CVE.ORG link : CVE-2023-45593
JSON object : View
Products Affected
ailux
- imx6
CWE