Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mhw2-47hc-23pg

Опубликовано: 26 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

Incorrect access control in the SPI Flash Chip of Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 allows physically proximate attackers to arbitrarily modify SPI flash regions, leading to a degradation of the security posture of the device.

Incorrect access control in the SPI Flash Chip of Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 allows physically proximate attackers to arbitrarily modify SPI flash regions, leading to a degradation of the security posture of the device.

EPSS

Процентиль: 12%
0.00041
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-1233
CWE-284

Связанные уязвимости

CVSS3: 3.5
nvd
6 месяцев назад

Incorrect access control in the SPI Flash Chip of Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 allows physically proximate attackers to arbitrarily modify SPI flash regions, leading to a degradation of the security posture of the device.

EPSS

Процентиль: 12%
0.00041
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-1233
CWE-284