Описание
Insufficient verification of data authenticity in Peloton TTR01 up to and including PTV55G allows an attacker with physical access to boot into a modified kernel/ramdisk without unlocking the bootloader.
Ссылки
- Third Party Advisory
- Third Party Advisory
- ExploitThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до ptv55g (включая)
Одновременно
cpe:2.3:o:onepeloton:ttr01_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:onepeloton:ttr01:-:*:*:*:*:*:*:*
EPSS
Процентиль: 7%
0.00027
Низкий
6.8 Medium
CVSS3
7.2 High
CVSS2
Дефекты
CWE-345
Связанные уязвимости
github
больше 3 лет назад
Insufficient verification of data authenticity in Peloton TTR01 up to and including PTV55G allows an attacker with physical access to boot into a modified kernel/ramdisk without unlocking the bootloader.
EPSS
Процентиль: 7%
0.00027
Низкий
6.8 Medium
CVSS3
7.2 High
CVSS2
Дефекты
CWE-345