7.8
CVE-2022-28806
- EPSS 0.11%
- Published 04.05.2022 15:15:13
- Last modified 21.11.2024 06:57:57
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
An issue was discovered on certain Fujitsu LIEFBOOK devices (A3510, U9310, U7511/U7411/U7311, U9311, E5510/E5410, U7510/U7410/U7310, E459/E449) with BIOS versions before v1.09 (A3510), v2.17 (U9310), v2.30 (U7511/U7411/U7311), v2.33 (U9311), v2.23 (E5510), v2.19 (U7510/U7410), v2.13 (U7310), and v1.09 (E459/E449). The FjGabiFlashCoreAbstractionSmm driver registers a Software System Management Interrupt (SWSMI) handler that is not sufficiently validated to ensure that the CommBuffer (or any other communication buffer's nested contents) are not pointing to SMRAM contents. A potential attacker can therefore write fixed data to SMRAM, which could lead to data corruption inside this memory (e.g., change the SMI handler's code or modify SMRAM map structures to break input pointer validation for other SMI handlers). Thus, the attacker could elevate privileges from ring 0 to ring -2 and execute arbitrary code in SMM.
Data is provided by the National Vulnerability Database (NVD)
Fujitsu ≫ Lifebook A3510 Firmware Version < 1.09
Fujitsu ≫ Lifebook U9310 Firmware Version < 2.17
Fujitsu ≫ Lifebook U7511 Firmware Version < 2.30
Fujitsu ≫ Lifebook U7411 Firmware Version < 2.30
Fujitsu ≫ Lifebook U7311 Firmware Version < 2.30
Fujitsu ≫ Lifebook U9311 Firmware Version <= 2.33
Fujitsu ≫ Lifebook E5510 Firmware Version < 2.23
Fujitsu ≫ Lifebook U7510 Firmware Version < 2.19
Fujitsu ≫ Lifebook U7410 Firmware Version < 2.19
Fujitsu ≫ Lifebook U7310 Firmware Version < 2.13
Fujitsu ≫ Lifebook E459 Firmware Version < 1.09
Fujitsu ≫ Lifebook E449 Firmware Version < 1.09
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.11% | 0.302 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.