CVE-2023-45593 is a CWE-184 "Incomplete List of Disallowed Inputs" vulnerability in the embedded Chromium browser of AiLux imx6 bundle versions below imx6_1.0.7-2. A physical attacker can exploit this flaw by manipulating alternative URLs to read arbitrary files, alter browser configurations, and impact the confidentiality, integrity, and availability of the device. With a CVSS score of 6.8 (Medium), this vulnerability requires physical access but has high impacts on all three security pillars. There is currently no known active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.7-2CPE matchmatch criteria | cpe:2.3:a:ailux:imx6:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.