CVE-2022-4020

Vulnerability in theHQSwSmiDxe DXE driver on some consumer Acer Notebook devices may allow an attacker with elevated privileges to modify UEFI Secure Boot settings by modifying an NVRAM variable.


ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.1 HIGH
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:H
ESETCNA
8.1 HIGH
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:H
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 17%
VendorProductVersion
aceraspire_a315-22g_firmware
-
aceraspire_a115-21_firmware
-
aceraspire_a315-22_firmware
-
acerextensa_ex215-21_firmware
-
acerextensa_ex215-21g_firmware
-
𝑥
= Vulnerable software versions