CyberRota Analysis
AI-GeneratedThe AWS FPGA Development Kit prior to version 2.3.4 contains a vulnerability that allows local users to exploit insecure permissions in a temporary file directory, potentially leading to arbitrary code execution with root privileges. This risk arises during the installation process, where crafted shell content can be placed in a world-writable directory. Organizations utilizing this toolkit should prioritize upgrading to the latest version to mitigate the risk of unauthorized access and system compromise.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Creation of a temporary file in a directory with insecure permissions in the FPGA management tool installation component in AWS FPGA Development Kit (aws-fpga) before 2.3.4 might allow local users to execute arbitrary code with root privileges via crafted shell content placed at a predictable path in a world-writable temporary directory, which the installation step reads after elevating its own privileges. To remediate this issue, users should upgrade to version 2.3.4.