PT-2023-23155 · Unknown · Securecore Technology 4

CVE-2023-31100

·

Publicado

2023-11-14

·

Atualizado

2025-09-25

CVSS v3.1

8.4

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions SecureCore Technology 4 versions 4.3.0.0 through 4.3.0.202 SecureCore Technology 4 versions 4.3.1.0 through 4.3.1.162 SecureCore Technology 4 versions 4.4.0.0 through 4.4.0.216 SecureCore Technology 4 versions 4.5.0.0 through 4.5.0.137
Description The issue is related to Improper Access Control in the SMI handler, allowing SPI flash modification.
Recommendations For SecureCore Technology 4 versions 4.3.0.0 through 4.3.0.202, update to version 4.3.0.203 or later. For SecureCore Technology 4 versions 4.3.1.0 through 4.3.1.162, update to version 4.3.1.163 or later. For SecureCore Technology 4 versions 4.4.0.0 through 4.4.0.216, update to version 4.4.0.217 or later. For SecureCore Technology 4 versions 4.5.0.0 through 4.5.0.137, update to version 4.5.0.138 or later.

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-31100

Produtos afetados

Securecore Technology 4