CVE-2018-16089 - CERT CVE
ID CVE-2018-16089
Sažetak In System Management Module (SMM) versions prior to 1.06, a field in the header of SMM firmware update images is insufficiently sanitized, allowing post-authentication command injection on the SMM as the root user.
Reference
CVSS
Base: 8.5
Impact: 10.0
Exploitability:6.8
Pristup
VektorSloženostAutentikacija
NETWORK MEDIUM SINGLE
Impact
PovjerljivostCjelovitostDostupnost
COMPLETE COMPLETE COMPLETE
CVSS vektor AV:N/AC:M/Au:S/C:C/I:C/A:C
Zadnje važnije ažuriranje 03-10-2019 - 00:03
Objavljeno 27-11-2018 - 14:29