A TOCTOU in ASP bootloader may allow an attacker to...
High severity
Unreviewed
Published
May 9, 2023
to the GitHub Advisory Database
•
Updated Apr 4, 2024
Description
Published by the National Vulnerability Database
May 9, 2023
Published to the GitHub Advisory Database
May 9, 2023
Last updated
Apr 4, 2024
A TOCTOU in ASP bootloader may allow an attacker
to tamper with the SPI ROM following data read to memory potentially resulting
in S3 data corruption and information disclosure.
References