Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pcxq-4x45-227m

Опубликовано: 17 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 7

Описание

An uncontrolled resource consumption vulnerability affects certain ASUS motherboards using Intel B460, B560, B660, B760, H410, H510, H610, H470, Z590, Z690, Z790, W480, W680 series chipsets. Exploitation requires physical access to internal expansion slots to install a specially crafted device and supporting software utility, and may lead to uncontrolled resource consumption that increases the risk of unauthorized direct memory access (DMA). Refer to the 'Security Update for UEFI firmware' section on the ASUS Security Advisory for more information.

An uncontrolled resource consumption vulnerability affects certain ASUS motherboards using Intel B460, B560, B660, B760, H410, H510, H610, H470, Z590, Z690, Z790, W480, W680 series chipsets. Exploitation requires physical access to internal expansion slots to install a specially crafted device and supporting software utility, and may lead to uncontrolled resource consumption that increases the risk of unauthorized direct memory access (DMA). Refer to the 'Security Update for UEFI firmware' section on the ASUS Security Advisory for more information.

EPSS

Процентиль: 6%
0.00026
Низкий

7 High

CVSS4

Дефекты

CWE-284

Связанные уязвимости

nvd
около 2 месяцев назад

An uncontrolled resource consumption vulnerability affects certain ASUS motherboards using Intel B460, B560, B660, B760, H410, H510, H610, H470, Z590, Z690, Z790, W480, W680 series chipsets. Exploitation requires physical access to internal expansion slots to install a specially crafted device and supporting software utility, and may lead to uncontrolled resource consumption that increases the risk of unauthorized direct memory access (DMA). Refer to the 'Security Update for UEFI firmware' section on the ASUS Security Advisory for more information.

CVSS3: 6.8
fstec
около 2 месяцев назад

Уязвимость микропрограммного обеспечения UEFI материнских плат ASUS на базе чипсетов Intel B460, B560, B660, B760, H410, H510, H610, H470, Z590, Z690, Z790, W480, W680, позволяющая нарушителю провести DMA-атаку и обойти существующие ограничения безопасности

EPSS

Процентиль: 6%
0.00026
Низкий

7 High

CVSS4

Дефекты

CWE-284