Input Validation Flaw in Phoenix SecureCore Technology Product
CVE-2023-5058
7.8HIGH
What is CVE-2023-5058?
The vulnerability occurs due to improper input validation in the processing of user-supplied splash screens during system boot in Phoenix SecureCore Technology 4. This can lead to denial-of-service attacks, resulting in system unavailability, or allow an attacker to execute arbitrary code with system privileges, potentially compromising the security of the device.
Affected Version(s)
SecureCore™ Technology™ 4 4.0