Loading vulnerability details…
CVSS v3.1
3.3
EPSS
0.26%
Published
Nov 14, 2023
Modified
Nov 21, 2024
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM records after memory content verification, potentially leading to loss of confidentiality or a denial of service.
CVSS Vector
CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:LWeaknesses (CWE)
Affected Products (186)
References (6)
...and 136 more