CVE Vulnerabilities

CVE-2022-38773

Published: Jan 10, 2023 | Modified: Jan 13, 2023
CVSS 3.x
6.8
MEDIUM
Source:
NVD
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Affected devices do not contain an Immutable Root of Trust in Hardware. With this the integrity of the code executed on the device can not be validated during load-time. An attacker with physical access to the device could use this to replace the boot image of the device and execute arbitrary code.

Affected Software

Name Vendor Start Version End Version
Simatic_drive_controller_cpu_1504d_tf_firmware Siemens - (including) - (including)

References