CVE-2023-29063

The FACSChorus workstation does not prevent physical access to its PCI express (PCIe) slots, which could allow a threat actor to insert a PCI card designed for memory capture. A threat actor can then isolate sensitive information such as a BitLocker encryption key from a dump of the workstation RAM during startup.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:bd:facschorus:5.0:*:*:*:*:*:*:*
cpe:2.3:a:bd:facschorus:5.1:*:*:*:*:*:*:*
cpe:2.3:h:hp:hp_z2_tower_g9:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:a:bd:facschorus:3.0:*:*:*:*:*:*:*
cpe:2.3:a:bd:facschorus:3.1:*:*:*:*:*:*:*
cpe:2.3:h:hp:hp_z2_tower_g5:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-11-28 21:15

Updated : 2023-12-05 14:45


NVD link : CVE-2023-29063

Mitre link : CVE-2023-29063

CVE.ORG link : CVE-2023-29063


JSON object : View

Products Affected

hp

  • hp_z2_tower_g9
  • hp_z2_tower_g5

bd

  • facschorus
CWE
CWE-306

Missing Authentication for Critical Function

CWE-1299

Missing Protection Mechanism for Alternate Hardware Interface