MEDIUM · 6.8

CVE-2019-16258

The bootloader of the homee Brain Cube V2 through 2.23.0 allows attackers with physical access to gain root access by manipulating the U-Boot environment via the CLI after connecting to the internal U...

Vulnerability Description

The bootloader of the homee Brain Cube V2 through 2.23.0 allows attackers with physical access to gain root access by manipulating the U-Boot environment via the CLI after connecting to the internal UART interface.

CVSS Score

6.8

MEDIUM

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
PHYSICAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
Hom.EeBrain Cube Core>= 2.0.0, <= 2.23.0
Hom.EeBrain CubeAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-16258?

CVE-2019-16258 is a vulnerability with a CVSS score of 6.8 (MEDIUM). The bootloader of the homee Brain Cube V2 through 2.23.0 allows attackers with physical access to gain root access by manipulating the U-Boot environment via the CLI after connecting to the internal U...

How severe is CVE-2019-16258?

CVE-2019-16258 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-16258?

Check the references section above for vendor advisories and patch information. Affected products include: Hom.Ee Brain Cube Core, Hom.Ee Brain Cube.