2023-11-15 00:55:21 +00:00
{
"id" : "CVE-2023-31100" ,
"sourceIdentifier" : "22d9ba52-f336-4b0d-bf1f-0efbdcc3c1de" ,
"published" : "2023-11-15T00:15:07.573" ,
2024-02-01 03:00:30 +00:00
"lastModified" : "2024-02-01T02:30:22.687" ,
2023-11-22 17:04:06 +00:00
"vulnStatus" : "Analyzed" ,
2023-11-15 00:55:21 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "Improper Access Control in SMI handler vulnerability in Phoenix SecureCore\u2122 Technology\u2122 4 allows SPI flash modification.\nThis issue affects SecureCore\u2122 Technology\u2122 4:\n\n\n * from 4.3.0.0 before 4.3.0.203\n * \n\nfrom \n\n4.3.1.0 before 4.3.1.163\n * \n\nfrom \n\n4.4.0.0 before 4.4.0.217\n * \n\nfrom \n\n4.5.0.0 before 4.5.0.138\n\n\n\n\n"
2023-11-22 17:04:06 +00:00
} ,
{
"lang" : "es" ,
"value" : "Control de Acceso Inadecuado en la vulnerabilidad del Control SMI en Phoenix SecureCore\u2122 Technology\u2122 4 permite la modificaci\u00f3n de flash SPI. Este problema afecta a SecureCore\u2122 Technology\u2122 4: * desde 4.3.0.0 anterior a 4.3.0.203 * desde 4.3.1.0 anterior a 4.3.1.163 * desde 4.4.0.0 anterior a 4.4.0.217 * desde 4.5.0.0 anterior a 4.5.0.138"
2023-11-15 00:55:21 +00:00
}
] ,
"metrics" : {
"cvssMetricV31" : [
2023-11-22 17:04:06 +00:00
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" ,
"attackVector" : "LOCAL" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "HIGH" ,
"availabilityImpact" : "HIGH" ,
"baseScore" : 7.1 ,
"baseSeverity" : "HIGH"
} ,
"exploitabilityScore" : 1.8 ,
"impactScore" : 5.2
} ,
2023-11-15 00:55:21 +00:00
{
"source" : "22d9ba52-f336-4b0d-bf1f-0efbdcc3c1de" ,
"type" : "Secondary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H" ,
"attackVector" : "LOCAL" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
"scope" : "CHANGED" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "HIGH" ,
"availabilityImpact" : "HIGH" ,
"baseScore" : 8.4 ,
"baseSeverity" : "HIGH"
} ,
"exploitabilityScore" : 2.0 ,
"impactScore" : 5.8
}
]
} ,
"weaknesses" : [
2023-11-22 17:04:06 +00:00
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "NVD-CWE-Other"
}
]
} ,
2023-11-15 00:55:21 +00:00
{
"source" : "22d9ba52-f336-4b0d-bf1f-0efbdcc3c1de" ,
"type" : "Secondary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-284"
}
]
}
] ,
2023-11-22 17:04:06 +00:00
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
2024-02-01 03:00:30 +00:00
"criteria" : "cpe:2.3:o:phoenix:securecore_technology:*:*:*:*:*:*:*:*" ,
2023-11-22 17:04:06 +00:00
"versionStartIncluding" : "4.3.0.0" ,
"versionEndExcluding" : "4.3.0.203" ,
2024-02-01 03:00:30 +00:00
"matchCriteriaId" : "E56DABBE-40F8-4A26-92C6-9506AA426673"
2023-11-22 17:04:06 +00:00
} ,
{
"vulnerable" : true ,
2024-02-01 03:00:30 +00:00
"criteria" : "cpe:2.3:o:phoenix:securecore_technology:*:*:*:*:*:*:*:*" ,
2023-11-22 17:04:06 +00:00
"versionStartIncluding" : "4.3.1.0" ,
"versionEndExcluding" : "4.3.1.163" ,
2024-02-01 03:00:30 +00:00
"matchCriteriaId" : "D2466200-7229-4412-83BE-E1B0FC076CCD"
2023-11-22 17:04:06 +00:00
} ,
{
"vulnerable" : true ,
2024-02-01 03:00:30 +00:00
"criteria" : "cpe:2.3:o:phoenix:securecore_technology:*:*:*:*:*:*:*:*" ,
2023-11-22 17:04:06 +00:00
"versionStartIncluding" : "4.4.0.0" ,
"versionEndExcluding" : "4.4.0.217" ,
2024-02-01 03:00:30 +00:00
"matchCriteriaId" : "7AE48D55-B352-497B-9E69-4BE0B0A35865"
2023-11-22 17:04:06 +00:00
} ,
{
"vulnerable" : true ,
2024-02-01 03:00:30 +00:00
"criteria" : "cpe:2.3:o:phoenix:securecore_technology:*:*:*:*:*:*:*:*" ,
2023-11-22 17:04:06 +00:00
"versionStartIncluding" : "4.5.0.0" ,
"versionEndExcluding" : "4.5.0.138" ,
2024-02-01 03:00:30 +00:00
"matchCriteriaId" : "DA9F0AF7-9C96-4523-B30F-78C2BEEE933C"
2023-11-22 17:04:06 +00:00
}
]
}
]
}
] ,
2023-11-15 00:55:21 +00:00
"references" : [
{
2023-11-15 03:00:22 +00:00
"url" : "https://www.phoenix.com/security-notifications/" ,
2023-11-22 17:04:06 +00:00
"source" : "22d9ba52-f336-4b0d-bf1f-0efbdcc3c1de" ,
"tags" : [
"Vendor Advisory"
]
2023-11-15 00:55:21 +00:00
}
]
}