- Description
- An issue was discovered in iscflashx64.sys 3.9.3.0 in Insyde H2OFFT 6.20.00. When handling IOCTL 0x22229a, the input used to allocate a buffer and copy memory is mishandled. This could cause memory corruption or a system crash.
- Source
- cve@mitre.org
- NVD status
- Modified
CVSS 3.1
- Type
- Primary
- Base score
- 7.1
- Impact score
- 5.2
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
- Severity
- HIGH
- nvd@nist.gov
- CWE-787
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:insyde:h2offt:6.20.00:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F6D12E08-642C-4101-AEE5-08891977CE27"
},
{
"criteria": "cpe:2.3:a:insyde:iscflashx64.sys:3.9.3.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "043174B7-0F25-47D3-807F-21D76356B83D"
}
],
"operator": "OR"
}
]
}
]