CVE-2023-52711

HIGH

Huawei Curiem-WFG9B Firmware - Improper Access Control via Exposed SMI Handler

Title source: llm
STIX 2.1

Description

Various Issues Due To Exposed SMI Handler in AmdPspP2CmboxV2. The first issue can be leveraged to bypass the protections that have been put in place by previous UEFI phases to prevent direct access to the SPI flash. The second issue can be used to both leak and corrupt SMM memory thus potentially leading code execution in SMM

Scores

CVSS v3 7.8
EPSS 0.0001
EPSS Percentile 0.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-284 CWE-401
Status published
Products (1)
huawei/curiem-wfg9b_firmware curiem-wfg9b_bios_2.28
Published May 28, 2024
Tracked Since Feb 18, 2026