PT-2023-23155 · Unknown · Securecore Technology 4

Published

2023-11-14

·

Updated

2025-09-25

·

CVE-2023-31100

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions SecureCore Technology 4 versions 4.3.0.0 through 4.3.0.202 SecureCore Technology 4 versions 4.3.1.0 through 4.3.1.162 SecureCore Technology 4 versions 4.4.0.0 through 4.4.0.216 SecureCore Technology 4 versions 4.5.0.0 through 4.5.0.137
Description The issue is related to Improper Access Control in the SMI handler, allowing SPI flash modification.
Recommendations For SecureCore Technology 4 versions 4.3.0.0 through 4.3.0.202, update to version 4.3.0.203 or later. For SecureCore Technology 4 versions 4.3.1.0 through 4.3.1.162, update to version 4.3.1.163 or later. For SecureCore Technology 4 versions 4.4.0.0 through 4.4.0.216, update to version 4.4.0.217 or later. For SecureCore Technology 4 versions 4.5.0.0 through 4.5.0.137, update to version 4.5.0.138 or later.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2023-31100

Affected Products

Securecore Technology 4