SB2023031518 - Secure Boot bypass in Trend Micro Endpoint Encryption Full Disk Encryption



SB2023031518 - Secure Boot bypass in Trend Micro Endpoint Encryption Full Disk Encryption

Published: March 15, 2023

Security Bulletin ID SB2023031518
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Physical access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Security features bypass (CVE-ID: CVE-2023-28005)

CWE-ID: CWE-254 - Security Features

CVSSv4: CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows an attacker to bypass Secure Boot restrictions.

the vulnerability exists due to incorrect implementation of the Secure Boot feature. An attacker with physical access to device can bypass the Secure Boot restrictions and gain unauthorized access to the system.


Remediation

Install update from vendor's website.