NA

CVE-2022-40297

Published: 09/09/2022 Updated: 11/04/2024
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

UBports Ubuntu Touch 16.04 allows the screen-unlock passcode to be used for a privileged shell via Sudo. This passcode is only four digits, far below typical length/complexity for a user account's password. NOTE: a third party states "The described attack cannot be executed as demonstrated.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ubports ubuntu touch 16.04

Github Repositories

CVE-2022-40297 - Proof of Concept: Privilege escalation in Ubuntu Touch 16.04 - by PIN Bruteforce

[UPDATE 09092022] I got new CVE for this vulnerability: CVE-2022-40297 Proof of Concept: Privilege escalation in Ubuntu Touch 1604 - by Passcode Bruteforce Ubuntu Touch allows you to "protect" devices with a 4-digit passcode Such a code was set in a demonstration device The problem is that the same 4-digit passcode then becomes a password that we can use with th