CVE-2019-12532
Summary
| CVE | CVE-2019-12532 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-08-26 18:15:00 UTC |
| Updated | 2022-04-29 12:30:00 UTC |
| Description | Improper access control in the Insyde software tools may allow an authenticated user to potentially enable escalation of privilege, or information disclosure via local access. This is a software vulnerability, not a firmware issue. Affected tools include: H2OFFT version 3.02~5.28, 100.00.00.00~100.00.08.23 and 200.00.00.01~200.00.00.05, H2OOAE before version 200.00.00.02, H2OSDE before version 200.00.00.07, H2OUVE before version 200.00.02.02, H2OPCM before version 100.00.06.00, H2OELV before version 100.00.02.08. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Insyde | H2oelv | All | All | All | All |
| Application | Insyde | H2oelv | All | All | All | All |
| Application | Insyde | H2offt | All | All | All | All |
| Application | Insyde | H2offt | All | All | All | All |
| Application | Insyde | H2offt | All | All | All | All |
| Application | Insyde | H2ooae | All | All | All | All |
| Application | Insyde | H2ooae | All | All | All | All |
| Application | Insyde | H2opcm | All | All | All | All |
| Application | Insyde | H2opcm | All | All | All | All |
| Application | Insyde | H2osde | All | All | All | All |
| Application | Insyde | H2osde | All | All | All | All |
| Application | Insyde | H2ouve | All | All | All | All |
| Application | Insyde | H2ouve | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Screwed Drivers – Signed, Sealed, Delivered - Eclypsium | MISC | eclypsium.com | Third Party Advisory |
| CVE-2019-12532 InsydeH2O Vulnerability in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | |
| Security Advisory | Insyde Software | CONFIRM | www.insyde.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.