Lucene search

K
nvd[email protected]NVD:CVE-2019-12532
HistoryAug 26, 2019 - 6:15 p.m.

CVE-2019-12532

2019-08-2618:15:11
web.nvd.nist.gov
6

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.5

Confidence

High

EPSS

0.001

Percentile

27.6%

Improper access control in the Insyde software tools may allow an authenticated user to potentially enable escalation of privilege, or information disclosure via local access. This is a software vulnerability, not a firmware issue. Affected tools include: H2OFFT version 3.02~5.28, 100.00.00.00~100.00.08.23 and 200.00.00.01~200.00.00.05, H2OOAE before version 200.00.00.02, H2OSDE before version 200.00.00.07, H2OUVE before version 200.00.02.02, H2OPCM before version 100.00.06.00, H2OELV before version 100.00.02.08.

Affected configurations

Nvd
Node
insydeh2oelvRange<100.00.02.08
OR
insydeh2offtRange3.025.28
OR
insydeh2offtRange100.00.00.00100.00.08.23
OR
insydeh2offtRange200.00.00.01200.00.00.05
OR
insydeh2ooaeRange<200.00.00.02
OR
insydeh2opcmRange<100.00.06.00
OR
insydeh2osdeRange<200.00.00.07
OR
insydeh2ouveRange<200.00.02.02
VendorProductVersionCPE
insydeh2oelv*cpe:2.3:a:insyde:h2oelv:*:*:*:*:*:*:*:*
insydeh2offt*cpe:2.3:a:insyde:h2offt:*:*:*:*:*:*:*:*
insydeh2ooae*cpe:2.3:a:insyde:h2ooae:*:*:*:*:*:*:*:*
insydeh2opcm*cpe:2.3:a:insyde:h2opcm:*:*:*:*:*:*:*:*
insydeh2osde*cpe:2.3:a:insyde:h2osde:*:*:*:*:*:*:*:*
insydeh2ouve*cpe:2.3:a:insyde:h2ouve:*:*:*:*:*:*:*:*

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.5

Confidence

High

EPSS

0.001

Percentile

27.6%

Related for NVD:CVE-2019-12532