Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c33r-r827-v785

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

In System Management Module (SMM) versions prior to 1.06, a field in the header of SMM firmware update images is insufficiently sanitized, allowing post-authentication command injection on the SMM as the root user.

In System Management Module (SMM) versions prior to 1.06, a field in the header of SMM firmware update images is insufficiently sanitized, allowing post-authentication command injection on the SMM as the root user.

EPSS

Процентиль: 78%
0.0116
Низкий

7.5 High

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 7.5
nvd
около 7 лет назад

In System Management Module (SMM) versions prior to 1.06, a field in the header of SMM firmware update images is insufficiently sanitized, allowing post-authentication command injection on the SMM as the root user.

EPSS

Процентиль: 78%
0.0116
Низкий

7.5 High

CVSS3

Дефекты

CWE-78