Sprecher: Vulnerable firmware verification
Published Jun 1, 2023
6.8
MEDIUMCVSS 3.1
EPSS 0.34%
Description
In Sprecher Automation SPRECON-E-C/P/T3 CPU in variant PU244x a vulnerable firmware verification has been identified. Through physical access and hardware manipulation, an attacker might be able to bypass hardware-based code verification and thus inject and execute arbitrary code and gain full access of the device.
Affected products
-
- Version allStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Sprecher Automation | SPRECON-E-C/P/T3 CPU PU244x | unaffected |
|
Configuration 1
Running on/with
- n/a
Configuration 2
Running on/with
- n/a
Configuration 3
Running on/with
- n/a
Configuration 4
- n/a
Running on/with
- n/a
Configuration 5
- n/a
Running on/with
- n/a
Configuration 6
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-51685 Advisory
- https://www.sprecher-automation.com/fileadmin/itSecurity/PDF/2022-12_Advisories.pdf MitigationVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-51685 | Advisory | |
| https://www.sprecher-automation.com/fileadmin/itSecurity/PDF/2022-12_Advisories.pdf | MitigationVendor Advisory |
Change history (0)
No recorded changes yet.