buildroot CVE Vulnerabilities & CVE List (6)

Products (CPE): — CVEs: 6

buildroot vulnerability overview

This page aggregates publicly disclosed CVE and security risk information related to buildroot, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

Vulnerability distribution trend (last 24 months)

Showing 16 of 6 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2023-45842 Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary command execution in the builder.This vulnerability is related to the `mxsldr` package. [email protected] 8.1 0.81% 2023-12-05 2026-06-17
CVE-2023-45841 Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary command execution in the builder.This vulnerability is related to the `versal-firmware` package. [email protected] 8.1 0.81% 2023-12-05 2026-06-17
CVE-2023-45840 Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary command execution in the builder.This vulnerability is related to the `riscv64-elf-toolchain` package. [email protected] 8.1 0.81% 2023-12-05 2026-06-17
CVE-2023-45839 Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary command execution in the builder.This vulnerability is related to the `aufs-util` package. [email protected] 8.1 0.81% 2023-12-05 2026-06-17
CVE-2023-45838 Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary command execution in the builder.This vulnerability is related to the `aufs` package. [email protected] 8.1 0.82% 2023-12-05 2026-06-17
CVE-2023-43608 A data integrity vulnerability exists in the BR_NO_CHECK_HASH_FOR functionality of Buildroot 2023.08.1 and dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary command execution in the builder. [email protected] 8.1 0.82% 2023-12-05 2026-06-17
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence