← volver
CVE-2020-25860CWE-367

CVE-2020-25860

3Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackepss 1.4%
probabilidad de explotación
1.4%top 28% de las CVE
explotación observada
noninguna fuente lo reporta
The install.c module in the Pengutronix RAUC update client prior to version 1.5 has a Time-of-Check Time-of-Use vulnerability, where signature verification on an update file takes place before the file is reopened for installation. An attacker who can modify the update file just before it is reopened can install arbitrary code on the device.
Productos afectados
n/a · Pengutronix RAUC