CVE-2018-12333

HIGH

ECOS Secure Boot Stick <5.6.5 - Code Injection

Title source: llm
STIX 2.1

Description

Insufficient Verification of Data Authenticity vulnerability in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacker to manipulate security relevant configurations and execute malicious code.

References (1)

Core 1
Core References
Mitigation, Third Party Advisory x_refsource_misc
https://telematik.prakinf.tu-ilmenau.de/ecos-sbs/advisory.html

Scores

CVSS v3 8.1
EPSS 0.0043
EPSS Percentile 34.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-345
Status published
Products (1)
ecos/secure_boot_stick_firmware 5.6.5
Published Jun 17, 2018
Tracked Since Feb 18, 2026