CVE-2022-38161

HIGH

Gumstix Overo SBC - Info Disclosure

Title source: llm
STIX 2.1

Description

The Gumstix Overo SBC on the VSKS board through 2022-08-09, as used on the Orlan-10 and other platforms, allows unrestricted remapping of the NOR flash memory containing the bitstream for the FPGA.

References (3)

Core 3
Core References
Third Party Advisory x_refsource_misc
https://github.com/subreption/birdwatch-report-1-repo
Technical Description, Third Party Advisory x_refsource_misc
https://subreption.com/downloads/reports/demystifying-the-orlan-10_opt.pdf

Scores

CVSS v3 7.5
EPSS 0.0057
EPSS Percentile 43.0%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (1)
gumstix/overo_sbc < 2022-08-09
Published Aug 11, 2022
Tracked Since Feb 18, 2026