// For flags

CVE-2023-29060

Lack of USB Whitelisting

Severity Score

5.7
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The FACSChorus workstation operating system does not restrict what devices can interact with its USB ports. If exploited, a threat actor with physical access to the workstation could gain access to system information and potentially exfiltrate data.

El sistema operativo de la estación de trabajo FACSChorus no restringe qué dispositivos pueden interactuar con sus puertos USB. Si se explota, un actor de amenazas con acceso físico a la estación de trabajo podría obtener acceso a la información del sistema y potencialmente filtrar datos.

*Credits: N/A
CVSS Scores
Attack Vector
Physical
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
High
Attack Vector
Physical
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
High
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2023-03-30 CVE Reserved
  • 2023-11-28 CVE Published
  • 2023-12-05 EPSS Updated
  • 2024-08-02 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-306: Missing Authentication for Critical Function
  • CWE-1299: Missing Protection Mechanism for Alternate Hardware Interface
CAPEC
  • CAPEC-457: USB Memory Attacks
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Bd
Search vendor "Bd"
Facschorus
Search vendor "Bd" for product "Facschorus"
5.0
Search vendor "Bd" for product "Facschorus" and version "5.0"
-
Affected
in Hp
Search vendor "Hp"
Hp Z2 Tower G9
Search vendor "Hp" for product "Hp Z2 Tower G9"
--
Safe
Bd
Search vendor "Bd"
Facschorus
Search vendor "Bd" for product "Facschorus"
5.1
Search vendor "Bd" for product "Facschorus" and version "5.1"
-
Affected
in Hp
Search vendor "Hp"
Hp Z2 Tower G9
Search vendor "Hp" for product "Hp Z2 Tower G9"
--
Safe
Bd
Search vendor "Bd"
Facschorus
Search vendor "Bd" for product "Facschorus"
3.0
Search vendor "Bd" for product "Facschorus" and version "3.0"
-
Affected
in Hp
Search vendor "Hp"
Hp Z2 Tower G5
Search vendor "Hp" for product "Hp Z2 Tower G5"
--
Safe
Bd
Search vendor "Bd"
Facschorus
Search vendor "Bd" for product "Facschorus"
3.1
Search vendor "Bd" for product "Facschorus" and version "3.1"
-
Affected
in Hp
Search vendor "Hp"
Hp Z2 Tower G5
Search vendor "Hp" for product "Hp Z2 Tower G5"
--
Safe