CVE-2019-12532

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
26/08/2019
Last modified:
29/04/2022

Description

Improper access control in the Insyde software tools may allow an authenticated user to potentially enable escalation of privilege, or information disclosure via local access. This is a software vulnerability, not a firmware issue. Affected tools include: H2OFFT version 3.02~5.28, 100.00.00.00~100.00.08.23 and 200.00.00.01~200.00.00.05, H2OOAE before version 200.00.00.02, H2OSDE before version 200.00.00.07, H2OUVE before version 200.00.02.02, H2OPCM before version 100.00.06.00, H2OELV before version 100.00.02.08.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:insyde:h2oelv:*:*:*:*:*:*:*:* 100.00.02.08 (excluding)
cpe:2.3:a:insyde:h2offt:*:*:*:*:*:*:*:* 3.02 (including) 5.28 (including)
cpe:2.3:a:insyde:h2offt:*:*:*:*:*:*:*:* 100.00.00.00 (including) 100.00.08.23 (including)
cpe:2.3:a:insyde:h2offt:*:*:*:*:*:*:*:* 200.00.00.01 (including) 200.00.00.05 (including)
cpe:2.3:a:insyde:h2ooae:*:*:*:*:*:*:*:* 200.00.00.02 (excluding)
cpe:2.3:a:insyde:h2opcm:*:*:*:*:*:*:*:* 100.00.06.00 (excluding)
cpe:2.3:a:insyde:h2osde:*:*:*:*:*:*:*:* 200.00.00.07 (excluding)
cpe:2.3:a:insyde:h2ouve:*:*:*:*:*:*:*:* 200.00.02.02 (excluding)