CVE-2018-12329: Infoleak
Published Jun 17, 2018
·Updated
Protection Mechanism Failure in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows a local attacker to duplicate an authentication factor via cloning.
Affected Software
2 affected components
ECOS Secure Boot Stick Firmware=5.6.5
ECOS Secure Boot Stick
Event History
Jun 17, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-12329?
CVE-2018-12329 is rated as high severity due to its potential to allow local attackers to duplicate an authentication factor.
2
How do I fix CVE-2018-12329?
To fix CVE-2018-12329, update your ECOS Secure Boot Stick firmware to a version after 5.6.5 that addresses this vulnerability.
3
What type of attack does CVE-2018-12329 facilitate?
CVE-2018-12329 facilitates a local attack that allows duplication of an authentication factor through cloning.
4
Which version of ECOS Secure Boot Stick firmware is affected by CVE-2018-12329?
ECOS Secure Boot Stick firmware version 5.6.5 is specifically affected by CVE-2018-12329.
5
Can hardware versions of the ECOS Secure Boot Stick be exploited by CVE-2018-12329?
No, CVE-2018-12329 affects only the firmware version 5.6.5 and not hardware versions of the ECOS Secure Boot Stick.