8.2
CVE-2022-4020
- EPSS 0.07%
- Veröffentlicht 28.11.2022 13:15:10
- Zuletzt bearbeitet 21.11.2024 07:34:27
- Quelle security@eset.com
- Teams Watchlist Login
- Unerledigt Login
Vulnerability in the HQSwSmiDxe DXE driver on some consumer Acer Notebook devices may allow an attacker with elevated privileges to modify UEFI Secure Boot settings by modifying an NVRAM variable.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Acer ≫ Aspire A315-22g Firmware Version-
Acer ≫ Aspire A115-21 Firmware Version-
Acer ≫ Aspire A315-22 Firmware Version-
Acer ≫ Extensa Ex215-21 Firmware Version-
Acer ≫ Extensa Ex215-21g Firmware Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.07% | 0.221 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 8.2 | 1.5 | 6 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
|
security@eset.com | 8.1 | 1.5 | 6 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:H
|
CWE-276 Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.