CVE-2023-29061: Lack of Adequate BIOS Authentication
There is no BIOS password on the FACSChorus workstation. A threat actor with physical access to the workstation can potentially exploit this vulnerability to access the BIOS configuration and modify the drive boot order and BIOS pre-boot authentication.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-29061?
CVE-2023-29061 refers to the lack of adequate BIOS authentication vulnerability.
What is the severity of CVE-2023-29061?
The severity of CVE-2023-29061 is medium with a severity value of 5.2.
Which software or devices are affected by CVE-2023-29061?
The FACSChorus version 5.0 and 5.1 software from BD as well as the HP Z2 Tower G9 and G5 devices are affected by CVE-2023-29061.
What can a threat actor potentially do with this vulnerability?
A threat actor with physical access to the FACSChorus workstation can potentially access the BIOS configuration, modify the drive boot order, and bypass the BIOS pre-boot authentication.
How can I mitigate the CVE-2023-29061 vulnerability?
To mitigate the CVE-2023-29061 vulnerability, enable a BIOS password on the FACSChorus workstation to prevent unauthorized access to the BIOS configuration and modify the drive boot order.