LOW🇬🇧 English

CVE-2023-29063

CVSS 2.4v3.1pub. 2023-11-28upd. 2024-11-21

Stacja robocza FACSChorus nie zapobiega fizycznym dostępem do slotów PCI express (PCIe), co pozwala atakującemu na wstawienie karty PCI zaprojektowanej do przechwycenia pamięci. Atakujący może następnie wyodrębnić wrażliwe informacje, takie jak klucz szyfrowania BitLocker z zrzutu pamięci RAM stacji roboczej podczas uruchamiania.

Pokaż oryginał (EN)

The FACSChorus workstation does not prevent physical access to its PCI express (PCIe) slots, which could allow a threat actor to insert a PCI card designed for memory capture. A threat actor can then isolate sensitive information such as a BitLocker encryption key from a dump of the workstation RAM during startup.

CVSS Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
  • Bd Facschorus

    APP
    Bd
    3.03.15.05.1
  • HP Z2 Tower G5

    HW
    Hp
    wszystkie wersje
  • HP Z2 Tower G9

    HW
    Hp
    wszystkie wersje
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2023-29060MEDIUM5.4ten sam produkt

The FACSChorus workstation operating system does not restrict what devices can interact with its USB ports. If...

CVE-2023-29061MEDIUM5.2ten sam produkt

There is no BIOS password on the FACSChorus workstation. A threat actor with physical access to the workstatio...

CVE-2023-29064MEDIUM4.1ten sam produkt

The FACSChorus software contains sensitive information stored in plaintext. A threat actor could gain hardcode...

CVE-2023-29065MEDIUM4.1ten sam produkt

The FACSChorus software database can be accessed directly with the privileges of the currently logged-in user....

CVE-2023-29062LOW3.8ten sam produkt

System operacyjny hostujący aplikację FACSChorus jest skonfigurowany tak, aby transmitować zahashowane dane uw...