CVE-2018-12337: Infoleak
Published Jun 17, 2018
·Updated
Reliance on Security Through Obscurity vulnerability in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacker to partially extract confidential configurations via user-space emulation.
Affected Software
2 affected components
ECOS Secure Boot Stick Firmware=5.6.5
ECOS Secure Boot Stick
Event History
Jun 17, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-12337?
The severity of CVE-2018-12337 is considered to be high due to the risk of confidential configuration extraction.
2
How do I fix CVE-2018-12337?
To fix CVE-2018-12337, update to a patched version of the ECOS Secure Boot Stick firmware that addresses this vulnerability.
3
What does CVE-2018-12337 exploit?
CVE-2018-12337 exploits a reliance on security through obscurity, allowing partial extraction of configurations.
4
Which version of the ECOS Secure Boot Stick is affected by CVE-2018-12337?
Version 5.6.5 of the ECOS Secure Boot Stick firmware is affected by CVE-2018-12337.
5
Is there a way for attackers to exploit CVE-2018-12337 remotely?
Yes, attackers can exploit CVE-2018-12337 via user-space emulation, potentially enabling remote attacks.