Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2022-48174: Busybox Arbitrary Code Execution in IoT Environments
CVE-2022-48174 · published 3 years ago
Summary
A critical vulnerability in Busybox allows attackers to execute arbitrary code on devices, potentially compromising the security of Internet of Vehicles systems. This could lead to unauthorized access, data theft, or system disruption. Update to Busybox 1.35 or later to mitigate this risk.
What to do
- Update debian busybox to version 1:1.30.1-6+deb11u1.
- Update debian busybox to version 1:1.35.0-4+deb12u1.
- Update debian busybox to version 1:1.37.0-1.
- Update alpine busybox to version 1.36.1-r2.
- Update alpine busybox to version 1.36.1-r1.
- Update alpine busybox to version 1.35.0-r310071.
- Update alpine rootio-busybox to version 1.35.0-r310071.
- Update alpine busybox to version 1.34.1-r70071.
- Update alpine rootio-busybox to version 1.34.1-r70071.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Debian:11 | debian | busybox |
< 1:1.30.1-6+deb11u1 Fix: upgrade to 1:1.30.1-6+deb11u1
|
| Debian:12 | debian | busybox |
< 1:1.35.0-4+deb12u1 Fix: upgrade to 1:1.35.0-4+deb12u1
|
| Debian:13 | debian | busybox |
< 1:1.37.0-1 Fix: upgrade to 1:1.37.0-1
|
| Debian:14 | debian | busybox |
< 1:1.37.0-1 Fix: upgrade to 1:1.37.0-1
|
| Alpine:v3.19 | alpine | busybox |
< 1.36.1-r2 Fix: upgrade to 1.36.1-r2
|
| Alpine:v3.20 | alpine | busybox |
< 1.36.1-r2 Fix: upgrade to 1.36.1-r2
|
| Alpine:v3.21 | alpine | busybox |
< 1.36.1-r2 Fix: upgrade to 1.36.1-r2
|
| Alpine:v3.22 | alpine | busybox |
< 1.36.1-r2 Fix: upgrade to 1.36.1-r2
|
| Alpine:v3.23 | alpine | busybox |
< 1.36.1-r2 Fix: upgrade to 1.36.1-r2
|
| Alpine:v3.24 | alpine | busybox |
< 1.36.1-r2 Fix: upgrade to 1.36.1-r2
|
| Alpine:v3.18 | alpine | busybox |
< 1.36.1-r1 Fix: upgrade to 1.36.1-r1
|
| Root:Alpine:3.17 | alpine | busybox |
< 1.35.0-r310071 Fix: upgrade to 1.35.0-r310071
|
| Root:Alpine:3.17 | alpine | rootio-busybox |
< 1.35.0-r310071 Fix: upgrade to 1.35.0-r310071
|
| Root:Alpine:3.15 | alpine | busybox |
< 1.34.1-r70071 Fix: upgrade to 1.34.1-r70071
|
| Root:Alpine:3.15 | alpine | rootio-busybox |
< 1.34.1-r70071 Fix: upgrade to 1.34.1-r70071
|
Original advisory text
There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitrary code execution.
There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitrary code execution.
References
Severity
9.8
Critical
CVSS 3.1: 9.8 (OSV)
Exploitation
EPSS 3%
Timeline
Published22 Aug 2023
Updated24 Sep 2026
First seen16 May 2026
Sources
DEBIAN-CVE-2022-48174 · OSV
CVE-2022-48174 · NVD
CVE-2022-48174 · MITRE
ALPINE-CVE-2022-48174 · OSV
Track software like this
Free during beta