PT-2023-12711 · Western Digital · Western Digital Ufs Host Boot Rom
Avri Altman
+1
·
Published
2023-01-23
·
Updated
2023-02-08
·
CVE-2022-23005
CVSS v3.1
8.7
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Western Digital UFS Host Boot ROM (affected versions not specified)
Description
A weakness has been identified in the UFS standard that could result in a security issue. This issue may exist in systems where the Host boot ROM code implements the UFS Boot feature to boot from UFS compliant storage devices. The UFS Boot feature is provided by UFS devices to support platforms that need to download the system boot loader from external non-volatile storage locations. Adversaries may disable the boot capability or revert to an old boot loader code if the host boot ROM code is improperly implemented. UFS Host Boot ROM implementers may be impacted by this issue. UFS devices are only impacted when connected to a vulnerable UFS Host and are not independently impacted by this issue.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this issue.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Western Digital Ufs Host Boot Rom