Lack of Adequate BIOS Authentication
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.2epss 0.4%
exploitation probability
0.4%top 69% of all CVEs
observed exploitation
nono source reports it
In short
The FACSChorus workstation has no BIOS password protection. Someone with physical access to the computer could change important system settings like boot order and security options.
Technical detail
CWE-306 vulnerability allowing unauthenticated BIOS access via physical local access. An attacker with direct hardware access can modify boot configurations and disable pre-boot authentication mechanisms, potentially enabling unauthorized system access or firmware tampering.
Summary generated and translated by AI from the official description.
There is no BIOS password on the FACSChorus workstation. A threat actor with physical access to the workstation can potentially exploit this vulnerability to access the BIOS configuration and modify the drive boot order and BIOS pre-boot authentication.
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Affected products
Becton, Dickinson and Company (BD) · FACSChorus