Improper Access Control Vulnerability in Phoenix SecureCore Technology 4
CVE-2023-31100

8.4HIGH

Key Information:

Vendor

Phoenix

Vendor
CVE Published:
15 November 2023

What is CVE-2023-31100?

The vulnerability in Phoenix SecureCore Technology 4 arises from improper access control in its SMI handler. This weakness allows unauthorized modification of the SPI flash, which could potentially compromise the security of devices utilizing this technology. Users of affected versions are strongly advised to update to the latest releases to mitigate exploitation risks.

Affected Version(s)

SecureCore™ Technology™ 4 4.3.0.0 < 4.3.0.203

SecureCore™ Technology™ 4 4.3.1.0 < 4.3.1.163

SecureCore™ Technology™ 4 4.4.0.0 < 4.4.0.217

References

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-31100 : Improper Access Control Vulnerability in Phoenix SecureCore Technology 4