VulnAI


EUVD-2023-54661

ID: EUVD-2023-54661

Severity: high

CVSS v4: Not provided

CVSS v3: 7.6 (CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)

CWE: None listed

Source: ENISA

Description

PAX A920 device allows to downgrade bootloader due to a bug in its version check. The signature is correctly checked and only bootloader signed by PAX can be used.  The attacker must have physical USB access to the device in order to exploit this vulnerability.

Timestamps

References

No references provided.