Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-phpw-4hqh-3488

Опубликовано: 17 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 7
CVSS3: 6.8

Описание

Certain motherboard models developed by ASRock and its subsidiaries, ASRockRack and ASRockInd. has a Protection Mechanism Failure vulnerability. Because IOMMU was not properly enabled, unauthenticated physical attackers can use a DMA-capable PCIe device to read and write arbitrary physical memory before the OS kernel and its security features are loaded.

Certain motherboard models developed by ASRock and its subsidiaries, ASRockRack and ASRockInd. has a Protection Mechanism Failure vulnerability. Because IOMMU was not properly enabled, unauthenticated physical attackers can use a DMA-capable PCIe device to read and write arbitrary physical memory before the OS kernel and its security features are loaded.

EPSS

Процентиль: 24%
0.00083
Низкий

7 High

CVSS4

6.8 Medium

CVSS3

Дефекты

CWE-693

Связанные уязвимости

CVSS3: 6.8
nvd
около 2 месяцев назад

Certain motherboard models developed by ASRock and its subsidiaries, ASRockRack and ASRockInd. has a Protection Mechanism Failure vulnerability. Because IOMMU was not properly enabled, unauthenticated physical attackers can use a DMA-capable PCIe device to read and write arbitrary physical memory before the OS kernel and its security features are loaded.

CVSS3: 6.8
fstec
около 2 месяцев назад

Уязвимость микропрограммного обеспечения UEFI материнских плат ASRock на базе чипсетов Intel 500, 600,700 и 800, позволяющая нарушителю провести DMA-атаку и обойти существующие ограничения безопасности

EPSS

Процентиль: 24%
0.00083
Низкий

7 High

CVSS4

6.8 Medium

CVSS3

Дефекты

CWE-693