8.2

CVE-2022-4020

Vulnerability in the HQSwSmiDxe DXE driver on some consumer Acer Notebook devices may allow an attacker with elevated privileges to modify UEFI Secure Boot settings by modifying an NVRAM variable.


Data is provided by the National Vulnerability Database (NVD)
AcerAspire A315-22g Firmware Version-
   AcerAspire A315-22g Version-
AcerAspire A115-21 Firmware Version-
   AcerAspire A115-21 Version-
AcerAspire A315-22 Firmware Version-
   AcerAspire A315-22 Version-
AcerExtensa Ex215-21 Firmware Version-
   AcerExtensa Ex215-21 Version-
AcerExtensa Ex215-21g Firmware Version-
   AcerExtensa Ex215-21g Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.07% 0.221
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.2 1.5 6
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
security@eset.com 8.1 1.5 6
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:H
CWE-276 Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.