Imx6
Vendor:
First CVE: Mar 5, 2024 · Active for 2 years
12
Total CVEs
More Total CVEs than 91% of tracked products
12.0
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
8.2
Avg CVSS
Higher Avg CVSS than 75% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Imx6 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 5, 2024
2 years ago
Most Recent CVE
Mar 5, 2024
875 days ago
CVE Severity & Scoring
Imx612 CVEs
33%
25%
42%
All CVEs353,173 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network10 (83.3%)
Unknown0 (0.0%)
Physical2 (16.7%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None11 (91.7%)
Unknown0 (0.0%)
Required1 (8.3%)
Privileges Required
Low4 (33.3%)
High0 (0.0%)
None8 (66.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-45600CRITICAL A CWE-613 “Insufficient Session Expiration” vulnerability in the web application, due to the session cookie “sessionid” lasting two weeks, facilitates session hijacking attacks aga | Mar 5, 2024 | 9.8 | 27 | NO | NO |
CVE-2023-5457CRITICAL A CWE-1269 “Product Released in Non-Release Configuration” vulnerability in the Django web framework used by the web application (due to the “debug” configuration parameter set to | Mar 5, 2024 | 9.8 | 26 | NO | NO |
CVE-2023-5456CRITICAL A CWE-798 “Use of Hard-coded Credentials” vulnerability in the MariaDB database of the web application allows a remote unauthenticated attacker to access the database service and a | Mar 5, 2024 | 9.8 | 26 | NO | NO |
CVE-2023-45597CRITICAL A CWE-1236 “Improper Neutralization of Formula Elements in a CSV File” vulnerability in the “file_configuration” functionality of the web application (concerning the function “expo | Mar 5, 2024 | 9.0 | 25 | NO | NO |
CVE-2023-45592CRITICAL A CWE-250 “Execution with Unnecessary Privileges” vulnerability in the embedded Chromium browser (due to the binary being executed with the “--no-sandbox” option and with root priv | Mar 5, 2024 | 9.8 | 25 | NO | NO |
CVE-2023-45595HIGH A CWE-434 “Unrestricted Upload of File with Dangerous Type” vulnerability in the “file_configuration” functionality of the web application allows a remote authenticated attacker to | Mar 5, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-45591HIGH A CWE-122 “Heap-based Buffer Overflow” vulnerability in the “logger_generic” function of the “Ax_rtu” binary allows a remote authenticated attacker to trigger a memory corruption i | Mar 5, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-45599HIGH A CWE-646 “Reliance on File Name or Extension of Externally-Supplied File” vulnerability in the “iec61850” functionality of the web application allows a remote authenticated attack | Mar 5, 2024 | 8.8 | 21 | NO | NO |
CVE-2023-45594MEDIUM A CWE-552 “Files or Directories Accessible to External Parties” vulnerability in the embedded Chromium browser allows a physical attacker to arbitrarily download/upload files to/fr | Mar 5, 2024 | 6.8 | 19 | NO | NO |
CVE-2023-45593MEDIUM A CWE-184 “Incomplete List of Disallowed Inputs” vulnerability in the embedded Chromium browser (concerning the handling of alternative URLs, other than “ http://localhost” ) allow | Mar 5, 2024 | 6.8 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (12 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (12 CVEs).
Media Mentions
Signals from CVEs in this product scope (12 CVEs).
Top CNAs Publishing CVEs For Imx6
Top CWEs
Versions
No cataloged versions.