Loading vulnerability details…
CVSS v3.1
7.4
EPSS
0.40%
Published
May 9, 2023
Modified
Jan 28, 2025
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
A TOCTOU in ASP bootloader may allow an attacker to tamper with the SPI ROM following data read to memory potentially resulting in S3 data corruption and information disclosure.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:NWeaknesses (CWE)
Affected Products (196)
References (4)
...and 146 more