Beveiligingsadvies

CVE-2018-20404

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2018-12-26 20:00:00
Laatst bijgewerkt 2024-08-05 11:58:19
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

ETK_E900.sys, a SmartETK driver for VIA Technologies EPIA-E900 system board, is vulnerable to denial of service attack via IOCTL 0x9C402048, which calls memmove and constantly fails on an arbitrary (uncontrollable) address, resulting in an eternal hang or a BSoD.