Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-38q7-2qqc-fvvr

Опубликовано: 09 мая 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

Time-of-check Time-of-use (TOCTOU) in the BIOS2PSP command may allow an attacker with a malicious BIOS to create a race condition causing the ASP bootloader to perform out-of-bounds SRAM reads upon an S3 resume event potentially leading to a denial of service.

Time-of-check Time-of-use (TOCTOU) in the BIOS2PSP command may allow an attacker with a malicious BIOS to create a race condition causing the ASP bootloader to perform out-of-bounds SRAM reads upon an S3 resume event potentially leading to a denial of service.

EPSS

Процентиль: 36%
0.00153
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-367

Связанные уязвимости

CVSS3: 5.9
nvd
больше 2 лет назад

Time-of-check Time-of-use (TOCTOU) in the BIOS2PSP command may allow an attacker with a malicious BIOS to create a race condition causing the ASP bootloader to perform out-of-bounds SRAM reads upon an S3 resume event potentially leading to a denial of service.

EPSS

Процентиль: 36%
0.00153
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-367