Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4qpv-c2wc-cr4r

Опубликовано: 10 янв. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.8

Описание

Affected devices do not contain an Immutable Root of Trust in Hardware. With this the integrity of the code executed on the device can not be validated during load-time. An attacker with physical access to the device could use this to replace the boot image of the device and execute arbitrary code.

Affected devices do not contain an Immutable Root of Trust in Hardware. With this the integrity of the code executed on the device can not be validated during load-time. An attacker with physical access to the device could use this to replace the boot image of the device and execute arbitrary code.

EPSS

Процентиль: 34%
0.00139
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-1326

Связанные уязвимости

CVSS3: 4.6
nvd
около 3 лет назад

Affected devices do not contain an Immutable Root of Trust in Hardware. With this the integrity of the code executed on the device can not be validated during load-time. An attacker with physical access to the device could use this to replace the boot image of the device and execute arbitrary code.

CVSS3: 4.6
fstec
около 3 лет назад

Уязвимость микропрограммного обеспечения программируемых логических контроллеров Siemens SIMATIC S7-1500 CPU Family, связанная с отсутствием неизменяемого корня доверия в оборудовании, позволяющая нарушителю заменить загрузочный образ устройства и выполнить произвольный код

EPSS

Процентиль: 34%
0.00139
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-1326