PT-2025-4174 · Smr · Smr

Andrea Toska

·

Published

2025-02-04

·

Updated

2025-02-12

·

CVE-2025-20892

CVSS v3.1

5.9

Medium

VectorAV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions SMR versions prior to January 2025 Release 1
Description A failure in the protection mechanism of the bootloader allows physical attackers to execute the fastboot command. User interaction is required to trigger this issue.
Recommendations For versions prior to January 2025 Release 1, update to a version that includes the fix for this issue to prevent physical attackers from executing the fastboot command. As a temporary workaround, consider restricting physical access to devices to minimize the risk of exploitation.

Fix

Related Identifiers

CVE-2025-20892

Affected Products

Smr