RSS   Vulnerabilities for 'Secure boot stick firmware'   RSS

2018-06-17
 
CVE-2018-12337

CWE-200
 

 
Reliance on Security Through Obscurity vulnerability in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacker to partially extract confidential configurations via user-space emulation.

 
 
CVE-2018-12336

CWE-200
 

 
Undocumented Factory Backdoor in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows the vendor to extract confidential information via remote root SSH access.

 
 
CVE-2018-12334

CWE-noinfo
 

 
Protection Mechanism Failure in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacker to compromise authentication and encryption keys via a virtualization attack.

 
 
CVE-2018-12333

CWE-345
 

 
Insufficient Verification of Data Authenticity vulnerability in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacker to manipulate security relevant configurations and execute malicious code.

 
 
CVE-2018-12332

CWE-459
 

 
Incomplete Cleanup vulnerability in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacker to compromise authentication and encryption keys via a compromised host PC after a reset.

 
 
CVE-2018-12330

CWE-noinfo
 

 
Protection Mechanism Failure in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacker to compromise authentication and encryption keys via compromised firmware.

 
 
CVE-2018-12329

CWE-200
 

 
Protection Mechanism Failure in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows a local attacker to duplicate an authentication factor via cloning.

 

 >>> Vendor: ECOS 3 Products
Embedded web servers
Secure boot stick firmware
System management appliance


Copyright 2024, cxsecurity.com

 

Back to Top