PT-2023-12089 · Unknown · Asp Bootloader

Published

2023-05-09

·

Updated

2025-01-28

·

CVE-2021-26356

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions ASP bootloader (affected versions not specified)
Description A Time-of-Check-to-Time-of-Use (TOCTOU) issue in the ASP bootloader may allow an attacker to tamper with the SPI ROM following data read to memory, potentially resulting in S3 data corruption and information disclosure.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Time Of Check To Time Of Use

Weakness Enumeration

Related Identifiers

CVE-2021-26356

Affected Products

Asp Bootloader