Debug Functions Unlockable Without Triggering Measured Boot
CVE-2023-43633

8.8HIGH

Key Information:

Status
Vendor
CVE Published:
21 September 2023

What is CVE-2023-43633?

An identified security configuration vulnerability in EVE OS allows unauthorized modification of the system's configuration during boot. This flaw occurs when the Pillar eve container checks for the presence of '/config/GlobalConfig/global.json'. If this file exists, it can overwrite critical configuration settings, enabling potential unauthorized access to the device. Attackers can exploit this to enable SSH access with custom 'authorized_keys', unlock USB ports to allow keyboard input, and permit VNC access—all without triggering the 'measured boot' mechanism. Notably, since the '/config' partition is mutable and not encrypted, attackers can gain full control over the device without changing the Platform Configuration Register (PCR) values.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

EVE OS 0 < 8.6.0

EVE OS 9.0.0 < 9.5.0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ilay Levi
.