Vulnerability Description
Armoury Crate Service’s logging function has insufficient validation to check if the log file is a symbolic link. A physical attacker with general user privilege can modify the log file property to a symbolic link that points to arbitrary system file, causing the logging function to overwrite the system file and disrupt the system.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Asus | Armoury Crate Service | < 5.2.10.0 |
Related Weaknesses (CWE)
References
- https://www.twcert.org.tw/tw/cp-132-6522-4eacb-1.htmlThird Party Advisory
- https://www.twcert.org.tw/tw/cp-132-6522-4eacb-1.htmlThird Party Advisory
FAQ
What is CVE-2022-38699?
CVE-2022-38699 is a vulnerability with a CVSS score of 5.9 (MEDIUM). Armoury Crate Service’s logging function has insufficient validation to check if the log file is a symbolic link. A physical attacker with general user privilege can modify the log file property to a ...
How severe is CVE-2022-38699?
CVE-2022-38699 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-38699?
Check the references section above for vendor advisories and patch information. Affected products include: Asus Armoury Crate Service.