8.4
CVE-2023-31100
- EPSS 0.06%
- Veröffentlicht 15.11.2023 00:15:07
- Zuletzt bearbeitet 25.09.2025 21:17:10
- Quelle 22d9ba52-f336-4b0d-bf1f-0efbdc
- CVE-Watchlists
- Unerledigt
Improper Access Control in SMI handler vulnerability in Phoenix SecureCore™ Technology™ 4 allows SPI flash modification. This issue affects SecureCore™ Technology™ 4: * from 4.3.0.0 before 4.3.0.203 * from 4.3.1.0 before 4.3.1.163 * from 4.4.0.0 before 4.4.0.217 * from 4.5.0.0 before 4.5.0.138
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Phoenixtech ≫ Securecore Technology Version >= 4.3.0.0 < 4.3.0.203
Phoenixtech ≫ Securecore Technology Version >= 4.3.1.0 < 4.3.1.163
Phoenixtech ≫ Securecore Technology Version >= 4.4.0.0 < 4.4.0.217
Phoenixtech ≫ Securecore Technology Version >= 4.5.0.0 < 4.5.0.138
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.06% | 0.185 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.1 | 1.8 | 5.2 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
|
| 22d9ba52-f336-4b0d-bf1f-0efbdcc3c1de | 8.4 | 2 | 5.8 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.