CVEbaza.plSłownik CWECWE-1328
Common Weakness Enumeration

CWE-1328

Security Version Number Mutable to Older Versions

Kategoria: BaseCVE: 5
Opis

Numer wersji bezpieczeństwa w sprzęcie jest zmienny, co umożliwia obniżenie (wycofanie) firmware'u rozruchowego do starszych, podatnych wersji kodu. Luka pozwala na ataki polegające na degradacji systemu bezpieczeństwa do podatnych konfiguracji.

Description (EN)

Security-version number in hardware is mutable, resulting in the ability to downgrade (roll-back) the boot firmware to vulnerable code versions.

Podatności CVE z CWE-1328 (5)
7.5
CVSS
HIGH
CVE-2025-5825

Autel MaxiCharger AC Wallbox Commercial Firmware Downgrade Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Wallbox Commercial charging stations. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target system in order to exploit this vulnerability. The specific flaw exists within the firmware update process. The issue results from the lack of proper validation of a firmware image before using it to perform an upgrade. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the device. Was ZDI-CAN-26354.

pub. 2025-06-25
6.8
CVSS
MEDIUM
CVE-2025-8321

Tesla Wall Connector Firmware Downgrade Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Tesla Wall Connector devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the firmware upgrade feature. The issue results from the lack of an anti-downgrade mechanism. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the device. Was ZDI-CAN-26299.

pub. 2025-07-30
4.3
CVSS
MEDIUM
CVE-2023-50738

A new feature to prevent Firmware downgrades was recently added to some Lexmark products. A method to override this downgrade protection has been identified.

pub. 2025-01-17
3.1
CVSS
LOW
CVE-2025-29989

Dell Client Platform BIOS zawiera podatność polegającą na możliwości zmiany numeru wersji bezpieczeństwa na starsze wersje. Atakujący z wysokimi uprawnieniami i dostępem lokalnym mógł potencjalnie wykorzystać tę podatność, prowadząc do odmowy aktualizacji BIOS-u.

pub. 2025-04-10
1.8
CVSS
LOW
CVE-2024-13870

W Bitdefender Box 1 (wersja oprogramowania 1.3.52.928 i starsze) istnieje podatność w kontroli dostępu, która pozwala niezautentykowanemu atakującemu na downgrade oprogramowania urządzenia do starszej, potencjalnie podatnej wersji podpisanego przez Bitdefender firmware'u. Atak wymaga uruchomienia Bitdefender BOX w Recovery Mode oraz obecności atakującego w zasięgu WiFi urządzenia BOX.

pub. 2025-03-12
Informacje
ID: CWE-1328
Typ: Base
Podatności: 5
MITRE CWE ↗
← Słownik CWE