PT-2020-28: Undocumented physical access to the system (SBI bootloader memory write)

HIGH
(7.6) CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Vulnerable software

Verifone
All

Severity level

Severity level: High
Impact: Undocumented physical access to the system (SBI bootloader memory write)
Access Vector: Remote

CVSS v3.1:
Base Score: 7.3
Vector: (AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)

CVE-2019-14715

Advisory status

01.10.2019 - Vendor gets vulnerability details
01.08.2020 - Vendor releases fixed version and details

Credits

The vulnerability was detected by Alex Stennikov, Dmitry Sklyarov, Egor Zaitsev, Positive Research Center (Positive Technologies Company)

Identifier:
CVE-2019-14715
Vendor:
Verifone
Vulnerable product:
All

Get in touch

Fill in the form and our specialists
will contact you shortly