CVE-2019-12532
26.08.2019, 18:15
Improper access control in the Insyde software tools may allow an authenticated user to potentially enable escalation of privilege, or information disclosure via local access. This is a software vulnerability, not a firmware issue. Affected tools include: H2OFFT version 3.02~5.28, 100.00.00.00~100.00.08.23 and 200.00.00.01~200.00.00.05, H2OOAE before version 200.00.00.02, H2OSDE before version 200.00.00.07, H2OUVE before version 200.00.02.02, H2OPCM before version 100.00.06.00, H2OELV before version 100.00.02.08.Enginsight
Vendor | Product | Version |
---|---|---|
insyde | h2oelv | 𝑥 < 100.00.02.08 |
insyde | h2offt | 3.02 ≤ 𝑥 ≤ 5.28 |
insyde | h2offt | 100.00.00.00 ≤ 𝑥 ≤ 100.00.08.23 |
insyde | h2offt | 200.00.00.01 ≤ 𝑥 ≤ 200.00.00.05 |
insyde | h2ooae | 𝑥 < 200.00.00.02 |
insyde | h2opcm | 𝑥 < 100.00.06.00 |
insyde | h2osde | 𝑥 < 200.00.00.07 |
insyde | h2ouve | 𝑥 < 200.00.02.02 |
𝑥
= Vulnerable software versions
References