all InfoSec news
CVE-2023-43633 (eve)
Sept. 21, 2023, 2:15 p.m. |
National Vulnerability Database web.nvd.nist.gov
“/config/GlobalConfig/global.json�.
If the file exists, it overrides the existing configuration on the device on boot.
This allows an attacker to change the system’s configuration, which also includes some
debug functions.
This could be used to unlock the ssh with custom “authorized_keys� via the
“debug.enable.ssh� key, similar to the “authorized_keys� finding that was noted before.
Other usages include unlocking the usb to enable the keyboard via the “debug.enable.usbâ€� …
attacker boot change configuration container cve debug device enable eve file functions global key ssh unlock
More from web.nvd.nist.gov / National Vulnerability Database
CVE-2023-45955 (lightstrip_firmware)
6 months, 1 week ago |
web.nvd.nist.gov
CVE-2023-21380 (android)
6 months, 1 week ago |
web.nvd.nist.gov
CVE-2023-21381 (android)
6 months, 1 week ago |
web.nvd.nist.gov
CVE-2023-21385 (android)
6 months, 1 week ago |
web.nvd.nist.gov
Jobs in InfoSec / Cybersecurity
Sr. Staff Security Engineer
@ Databricks | San Francisco, California
Security Engineer
@ Nomi Health | Austin, Texas
Senior Principal Consultant, Security Architecture
@ 6point6 | Manchester, United Kingdom
Cyber Policy Advisor
@ IntelliBridge | McLean, VA, McLean, VA, US
TW Full Stack Software Engineer (Access Control & Intrusion Systems)
@ Bosch Group | Taipei, Taiwan
Cyber Software Engineer
@ Peraton | Annapolis Junction, MD, United States