CVE-2022-23220

USBView 2.1 before 2.2 allows some local users (e.g., ones logged in via SSH) to execute arbitrary code as root because certain Polkit settings (e.g., allow_any=yes) for pkexec disable the authentication requirement. Code execution can, for example, use the --gtk-module option. This affects Ubuntu, Debian, and Gentoo.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 24%
VendorProductVersion
usbview_projectusbview
𝑥
< 2.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
usbview
bullseye (security)
2.0-21-g6fe2f4f-2+deb11u1
fixed
bullseye
2.0-21-g6fe2f4f-2+deb11u1
fixed
stretch
not-affected
bookworm
3.0-3
fixed
sid
3.1-1
fixed
trixie
3.1-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
usbview
lunar
not-affected
kinetic
not-affected
jammy
Fixed 2.0-21-g6fe2f4f-2ubuntu1
released
impish
Fixed 2.0-21-g6fe2f4f-2ubuntu0.21.10.3
released
hirsute
ignored
focal
Fixed 2.0-21-g6fe2f4f-2ubuntu0.20.04.1
released
bionic
Fixed 2.0-21-g6fe2f4f-1ubuntu1.1
released
xenial
not-affected