Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Insyde Subscribe
Filtered by product H2offt
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-12532 1 Insyde 6 H2oelv, H2offt, H2ooae and 3 more 2022-04-29 4.6 MEDIUM 7.8 HIGH
Improper access control in the Insyde software tools may allow an authenticated user to potentially enable escalation of privilege, or information disclosure via local access. This is a software vulnerability, not a firmware issue. Affected tools include: H2OFFT version 3.02~5.28, 100.00.00.00~100.00.08.23 and 200.00.00.01~200.00.00.05, H2OOAE before version 200.00.00.02, H2OSDE before version 200.00.00.07, H2OUVE before version 200.00.02.02, H2OPCM before version 100.00.06.00, H2OELV before version 100.00.02.08.