Vulnerability CVE-2019-6192


Published: 2019-12-10

Description:
A potential vulnerability has been reported in Lenovo Power Management Driver versions prior to 1.67.17.48 leading to a buffer overflow which could cause a denial of service.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
Lenovo Power Management Driver 1.67.17.48 pmdrvs.sys Denial of Service (PoC)
Nassim Asrir
30.12.2019

Type:

CWE-120

(Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'))

CVSS2 => (AV:L/AC:L/Au:N/C:N/I:N/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
2.1/10
2.9/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
None
Partial

 References:
http://packetstormsecurity.com/files/155656/Lenovo-Power-Management-Driver-Buffer-Overflow.html
https://support.lenovo.com/solutions/LEN-29334

Copyright 2024, cxsecurity.com

 

Back to Top