The permission system implemented and enforced by the GarminOS TVM component in CIQ API version 1.0.0 through 4.1.7 can be bypassed entirely. A malicious application with specially crafted code and data sections could access restricted CIQ modules, call their functions and disclose sensitive data such as user profile information and GPS coordinates, among others.
Metrics
Affected Vendors & Products
References
History
Tue, 21 Jan 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-863 | |
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-01-21T14:58:47.381Z
Reserved: 2023-01-11T00:00:00
Link: CVE-2023-23299

Updated: 2024-08-02T10:28:40.605Z

Status : Modified
Published: 2023-05-23T20:15:09.330
Modified: 2025-01-21T15:15:10.590
Link: CVE-2023-23299

No data.