CVE-2023-48696 is a critical remote code execution vulnerability affecting Azure RTOS USBX, specifically in components related to CDC ACM in versions 6.2.1 and below. An unauthenticated attacker can exploit expired pointer dereferences to achieve full compromise of the system. With a CVSS score of 9.8, this vulnerability poses a severe risk, allowing for complete confidentiality, integrity, and availability impact. While no public exploits, Metasploit modules, or active exploitation have been observed, users are strongly advised to upgrade to USBX release 6.3.0 as there are no known workarounds.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.3.0CPE matchmatch criteria | cpe:2.3:a:eclipse:threadx_usbx:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.