CVE-2023-29060

The FACSChorus workstation operating system does not restrict what devices can interact with its USB ports. If exploited, a threat actor with physical access to the workstation could gain access to system information and potentially exfiltrate data.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:h:hp:hp_z2_tower_g9:-:*:*:*:*:*:*:*
OR cpe:2.3:a:bd:facschorus:5.0:*:*:*:*:*:*:*
cpe:2.3:a:bd:facschorus:5.1:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:h:hp:hp_z2_tower_g5:-:*:*:*:*:*:*:*
OR cpe:2.3:a:bd:facschorus:3.0:*:*:*:*:*:*:*
cpe:2.3:a:bd:facschorus:3.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-11-28 20:15

Updated : 2023-12-05 14:44


NVD link : CVE-2023-29060

Mitre link : CVE-2023-29060

CVE.ORG link : CVE-2023-29060


JSON object : View

Products Affected

hp

  • hp_z2_tower_g9
  • hp_z2_tower_g5

bd

  • facschorus
CWE
CWE-306

Missing Authentication for Critical Function

CWE-1299

Missing Protection Mechanism for Alternate Hardware Interface