Exposed IOCTL with insufficient access control issue exists in cg6kwin2k.sys prior to 2.1.7.0. By sending a specific IOCTL request, a user without the administrator privilege may perform I/O to arbitrary hardware port or physical address, resulting in erasing or altering the firmware.
References
Configurations
No configuration.
History
21 Nov 2024, 09:07
Type | Values Removed | Values Added |
---|---|---|
References | () https://jvn.jp/en/vu/JVNVU90671953/ - | |
References | () https://sangomakb.atlassian.net/wiki/spaces/DVC/pages/45351279/Natural+Access+Software+Download - |
07 Nov 2024, 17:35
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-522 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.1 |
25 Mar 2024, 13:47
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
25 Mar 2024, 07:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-03-25 07:15
Updated : 2024-11-21 09:07
NVD link : CVE-2024-29216
Mitre link : CVE-2024-29216
CVE.ORG link : CVE-2024-29216
JSON object : View
Products Affected
No product.
CWE
CWE-522
Insufficiently Protected Credentials