Lucene search

K
nvd[email protected]NVD:CVE-2022-24351
HistoryDec 16, 2023 - 2:15 a.m.

CVE-2022-24351

2023-12-1602:15:07
CWE-367
web.nvd.nist.gov
4
insydeh2o
race-condition
vulnerability
kernel
data alteration

CVSS3

4.7

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N

EPSS

0

Percentile

9.0%

TOCTOU race-condition vulnerability in Insyde InsydeH2O with Kernel 5.2 before version 05.27.29, Kernel 5.3 before version 05.36.29, Kernel 5.4 version before 05.44.13, and Kernel 5.5 before version 05.52.13 allows an attacker to alter data and code used by the remainder of the boot process.

Affected configurations

Nvd
Node
insydeinsydeh2oRange5.25.2.05.27.29
OR
insydeinsydeh2oRange5.35.3.05.36.29
OR
insydeinsydeh2oRange5.45.4.05.44.13
OR
insydeinsydeh2oRange5.55.5.05.52.13
VendorProductVersionCPE
insydeinsydeh2o*cpe:2.3:a:insyde:insydeh2o:*:*:*:*:*:*:*:*

CVSS3

4.7

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N

EPSS

0

Percentile

9.0%

Related for NVD:CVE-2022-24351