Lucene search

K
cveMitreCVE-2022-34325
HistoryNov 14, 2022 - 11:15 p.m.

CVE-2022-34325

2022-11-1423:15:11
CWE-367
mitre
web.nvd.nist.gov
38
5
cve-2022-34325
dma transactions
smram corruption
storagesecuritycommanddxe
toctou attack
nvd
insyde engineering

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

EPSS

0

Percentile

12.6%

DMA transactions which are targeted at input buffers used for the StorageSecurityCommandDxe software SMI handler could cause SMRAM corruption through a TOCTOU attack. DMA transactions which are targeted at input buffers used for the software SMI handler used by the StorageSecurityCommandDxe driver could cause SMRAM corruption. This issue was discovered by Insyde engineering based on the general description provided by

Affected configurations

Nvd
Node
insydeinsydeh2oRange5.305.36.23
Node
insydeinsydeh2oRange5.205.27.23
Node
insydeinsydeh2oRange5.405.44.23
Node
insydeinsydeh2oRange5.505.52.23
VendorProductVersionCPE
insydeinsydeh2o*cpe:2.3:a:insyde:insydeh2o:*:*:*:*:*:*:*:*

Social References

More

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

EPSS

0

Percentile

12.6%

Related for CVE-2022-34325