CVE-2019-12532
Improper access control in the Insyde software tools may allow an authenticated user to potentially enable escalation of privilege, or information disclosure via local access.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.40%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Improper access control in the Insyde software tools may allow an authenticated user to potentially enable escalation of privilege, or information disclosure via local access. This is a software vulnerability, not a firmware issue. Affected tools include: H2OFFT version 3.02~5.28, 100.00.00.00~100.00.08.23 and 200.00.00.01~200.00.00.05, H2OOAE before version 200.00.00.02, H2OSDE before version 200.00.00.07, H2OUVE before version 200.00.02.02, H2OPCM before version 100.00.06.00, H2OELV before version 100.00.02.08.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.40% probability · 34th percentile
- CISA KEV
- Not listed
- Affected
- insyde/h2oelv · insyde/h2offt · insyde/h2ooae · insyde/h2opcm · insyde/h2osde · insyde/h2ouve
- Source
- cve@mitre.org
References
- https://eclypsium.com/2019/08/10/screwed-drivers-signed-sealed-delivered/Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220223-0004/Third Party Advisory
- https://www.insyde.com/security-pledge/SA-2019001Vendor Advisory
- https://eclypsium.com/2019/08/10/screwed-drivers-signed-sealed-delivered/Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220223-0004/Third Party Advisory
- https://www.insyde.com/security-pledge/SA-2019001Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.