PT-2022-5688 · Cisco · Cisco Secure Firewalls 3100 Series+1
Published
2022-11-09
·
Updated
2024-01-25
·
CVE-2022-20826
CVSS v3.1
6.8
Medium
| Vector | AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco Secure Firewalls 3100 Series versions (affected versions not specified)
Description
A vulnerability in the secure boot implementation could allow an unauthenticated attacker with physical access to the device to bypass the secure boot functionality. This issue is due to a logic error in the boot process. An attacker could exploit this by injecting malicious code into a specific memory location during the boot process, potentially allowing the execution of persistent code at boot time and breaking the chain of trust.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Asa
Cisco Secure Firewalls 3100 Series