7.8
CVE-2023-52547
- EPSS 0.02%
- Veröffentlicht 28.05.2024 07:15:08
- Zuletzt bearbeitet 17.01.2025 18:32:12
- Quelle psirt@huawei.com
- Teams Watchlist Login
- Unerledigt Login
Huawei Matebook D16(Model: CREM-WXX9, BIOS: v2.26. Memory Corruption in SMI Handler of HddPassword SMM Module. This can be leveraged by a malicious OS attacker to corrupt data structures stored at the beginning of SMRAM and can potentially lead to code execution in SMM.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Huawei ≫ Curiem-wfg9b Firmware Versionota-curiem-bios-2.29
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.02% | 0.034 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
psirt@huawei.com | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-130 Improper Handling of Length Parameter Inconsistency
The product parses a formatted message or structure, but it does not handle or incorrectly handles a length field that is inconsistent with the actual length of the associated data.
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.