Lucene search

K
cve[email protected]CVE-2022-24351
HistoryDec 16, 2023 - 2:15 a.m.

CVE-2022-24351

2023-12-1602:15:07
CWE-367
web.nvd.nist.gov
9
cve-2022-24351
toctou
race condition
vulnerability
insyde insydeh2o
kernel 5.2
kernel 5.3
kernel 5.4
kernel 5.5
nvd

4.7 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N

4.9 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%

TOCTOU race-condition vulnerability in Insyde InsydeH2O with Kernel 5.2 before version 05.27.29, Kernel 5.3 before version 05.36.29, Kernel 5.4 version before 05.44.13, and Kernel 5.5 before version 05.52.13 allows an attacker to alter data and code used by the remainder of the boot process.

Affected configurations

NVD
Node
insydeinsydeh2oRange5.25.2.05.27.29
OR
insydeinsydeh2oRange5.35.3.05.36.29
OR
insydeinsydeh2oRange5.45.4.05.44.13
OR
insydeinsydeh2oRange5.55.5.05.52.13

4.7 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N

4.9 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%

Related for CVE-2022-24351