CVE-2025-20034 - CERT CVE
ID CVE-2025-20034
Sažetak Improper input validation in the BackupBiosUpdate UEFI firmware SmiVariable driver for the Intel(R) Server D50DNP and M50FCP boards before version R01.02.0003 may allow a privileged user to potentially enable information disclosure via local access.
Reference
CVSS
Base: 5.3
Impact: 4.0
Exploitability:0.8
Pristup
VektorSloženostAutentikacija
LOCAL HIGH HIGH
Impact
PovjerljivostCjelovitostDostupnost
HIGH NONE NONE
CVSS vektor CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N
Zadnje važnije ažuriranje 13-05-2025 - 21:16
Objavljeno 13-05-2025 - 21:16