« Volver al listado

CVE-2023-5058

Estado: AnalizadaAlta (7.8)—

Improper Input Validation in the processing of user-supplied splash screen during system boot in Phoenix SecureCore™ Technology™ 4 potentially allows denial-of-service attacks or arbitrary code execution.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-5058",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "22d9ba52-f336-4b0d-bf1f-0efbdcc3c1de",
      "affectedData": [
        {
          "vendor": "Phoenix",
          "product": "SecureCore™ Technology™ 4",
          "versions": [
            {
              "status": "affected",
              "version": "4.0"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2023-12-07T23:15:07.490",
  "references": [
    {
      "url": "https://phoenixtech.com/phoenix-security-notifications/cve-2023-5058/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "22d9ba52-f336-4b0d-bf1f-0efbdcc3c1de"
    },
    {
      "url": "https://www.kb.cert.org/vuls/id/811862",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "22d9ba52-f336-4b0d-bf1f-0efbdcc3c1de"
    },
    {
      "url": "https://www.kb.cert.org/vuls/id/811862",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.phoenix.com/security-notifications/",
      "tags": [
        "Not Applicable"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.phoenix.com/security-notifications/cve-2023-5058/",
      "tags": [
        "Not Applicable"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "22d9ba52-f336-4b0d-bf1f-0efbdcc3c1de",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Improper Input Validation in the processing of user-supplied splash screen during system boot in Phoenix SecureCore™ Technology™ 4 potentially allows denial-of-service attacks or arbitrary code execution."
    },
    {
      "lang": "es",
      "value": "La validación de entrada inadecuada en el procesamiento de la pantalla de presentación proporcionada por el usuario durante el inicio del sistema en Phoenix SecureCore™ Technology™ 4 potencialmente permite ataques de denegación de servicio o ejecución de código arbitrario."
    }
  ],
  "lastModified": "2026-06-17T06:47:27.443",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:phoenixtech:securecore_technology:4.*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BFBB3510-AFF0-4C04-BB87-5ACD5E41B752"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "22d9ba52-f336-4b0d-bf1f-0efbdcc3c1de"
}