7.8

CVE-2022-21933

ASUS VivoMini/Mini PC - improper input validation

ASUS VivoMini/Mini PC device has an improper input validation vulnerability. A local attacker with system privilege can use system management interrupt (SMI) to modify memory, resulting in arbitrary code execution for controlling the system or disrupting service.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Asus ≫ Vc65-c1 Firmware Version < 1302
   Asus ≫ Vc65-c1 Version -
Asus ≫ Pb60v Firmware Version < 1302
   Asus ≫ Pb60v Version -
Asus ≫ Pb60g Firmware Version < 1302
   Asus ≫ Pb60g Version -
Asus ≫ Pb60s Firmware Version < 1302
   Asus ≫ Pb60s Version -
Asus ≫ Pa90 Firmware Version < 1401
   Asus ≫ Pa90 Version -
Asus ≫ Pb50 Firmware Version < 902
   Asus ≫ Pb50 Version -
Asus ≫ Pb60 Firmware Version < 1502
   Asus ≫ Pb60 Version -
Asus ≫ Pb61v Firmware Version < 601
   Asus ≫ Pb61v Version -
Asus ≫ Ts10 Firmware Version < 609
   Asus ≫ Ts10 Version -
Asus ≫ Pn40 Firmware Version < 2201
   Asus ≫ Pn40 Version -
Asus ≫ Pn60 Firmware Version < 808
   Asus ≫ Pn60 Version -
Asus ≫ Pn30 Firmware Version < 320
   Asus ≫ Pn30 Version -
Asus ≫ Un65u Firmware Version < 618
   Asus ≫ Un65u Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.27% 0.189
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
Cert TW 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://www.twcert.org.tw/tw/cp-132-5547-34bc4-1.html
Third Party Advisory