// For flags

CVE-2023-29063

Lack of DMA Access Protections

Severity Score

2.4
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The FACSChorus workstation does not prevent physical access to its PCI express (PCIe) slots, which could allow a threat actor to insert a PCI card designed for memory capture. A threat actor can then isolate sensitive information such as a BitLocker encryption key from a dump of the workstation RAM during startup.

La estación de trabajo FACSChorus no impide el acceso físico a sus ranuras PCI express (PCIe), lo que podría permitir que un actor de amenazas inserte una tarjeta PCI diseñada para la captura de memoria. Luego, un actor de amenazas puede aislar información confidencial, como una clave de cifrado BitLocker, de un volcado de la RAM de la estación de trabajo durante el inicio.

*Credits: N/A
CVSS Scores
Attack Vector
Physical
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2023-03-30 CVE Reserved
  • 2023-11-28 CVE Published
  • 2023-12-05 EPSS Updated
  • 2024-08-02 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-306: Missing Authentication for Critical Function
  • CWE-1299: Missing Protection Mechanism for Alternate Hardware Interface
CAPEC
  • CAPEC-121: Exploit Non-Production Interfaces
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Bd
Search vendor "Bd"
Facschorus
Search vendor "Bd" for product "Facschorus"
5.0
Search vendor "Bd" for product "Facschorus" and version "5.0"
-
Affected
in Hp
Search vendor "Hp"
Hp Z2 Tower G9
Search vendor "Hp" for product "Hp Z2 Tower G9"
--
Safe
Bd
Search vendor "Bd"
Facschorus
Search vendor "Bd" for product "Facschorus"
5.1
Search vendor "Bd" for product "Facschorus" and version "5.1"
-
Affected
in Hp
Search vendor "Hp"
Hp Z2 Tower G9
Search vendor "Hp" for product "Hp Z2 Tower G9"
--
Safe
Bd
Search vendor "Bd"
Facschorus
Search vendor "Bd" for product "Facschorus"
3.0
Search vendor "Bd" for product "Facschorus" and version "3.0"
-
Affected
in Hp
Search vendor "Hp"
Hp Z2 Tower G5
Search vendor "Hp" for product "Hp Z2 Tower G5"
--
Safe
Bd
Search vendor "Bd"
Facschorus
Search vendor "Bd" for product "Facschorus"
3.1
Search vendor "Bd" for product "Facschorus" and version "3.1"
-
Affected
in Hp
Search vendor "Hp"
Hp Z2 Tower G5
Search vendor "Hp" for product "Hp Z2 Tower G5"
--
Safe