CVE-2022-43703
Estado: ModificadaAlta (7.8)—
An installer that loads or executes files using an unconstrained search path may be vulnerable to substitute files under control of an attacker being loaded or executed instead of the intended files.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.19%
- Percentil entre todas las CVEs puntuadas: 8
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-427
- CWE-427
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-43703",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "arm-security@arm.com",
"affectedData": [
{
"vendor": "Arm Ltd",
"modules": [
"installer"
],
"product": "Arm Compiler 5 (AC5), Arm Compiler for Embedded 6 (AC6), Fast Models (FM), Arm Compiler for Embedded FuSA (ACEF), Arm Development Studio (ADS), Arm Forge (AF), Arm Mobile Studio (AMS), DS-5 Development Studio, Fast Models (FM), GNU Toolchain (GT), Keil MDK (KMDK), Mbed Studio (MS)",
"versions": [
{
"status": "affected",
"version": "AC5 All Releases, AC6 Releases prior to 6.20, ACEF All Releases, ADS All Releases, AF Releases prior to 22.1, AMS All releases, DS5 All Releases, FM All Releases, GT All Releases, KMDK All Releases, MS All Releases"
}
],
"defaultStatus": "affected"
}
]
}
],
"published": "2023-07-27T22:15:12.870",
"references": [
{
"url": "https://developer.arm.com/documentation/ka005596/latest",
"tags": [
"Vendor Advisory"
],
"source": "arm-security@arm.com"
},
{
"url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00930.html",
"source": "arm-security@arm.com"
},
{
"url": "https://developer.arm.com/documentation/ka005596/latest",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00930.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "arm-security@arm.com",
"description": [
{
"lang": "en",
"value": "CWE-427"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-427"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An installer that loads or executes files using an unconstrained search path may be vulnerable to substitute files under control of an attacker being loaded or executed instead of the intended files."
}
],
"lastModified": "2026-06-17T05:07:10.363",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:arm:arm_development_studio:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "241064F9-9B76-41FA-A8B5-4FBCDE51BAD2"
},
{
"criteria": "cpe:2.3:a:arm:ds_development_studio:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "30B049E4-59A7-47D8-A491-D947C4AAD4AC",
"versionEndIncluding": "5.29.3",
"versionStartIncluding": "5.0.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "arm-security@arm.com"
}