An issue in the DeviceloControl function of ITE Tech. Inc ITE IO Access v1.0.0.0 allows attackers to perform arbitrary port read and write actions via supplying crafted IOCTL requests.
History

Tue, 07 Jan 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1284
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 06 Jan 2025 19:00:00 +0000

Type Values Removed Values Added
Description An issue in the DeviceloControl function of ITE Tech. Inc ITE IO Access v1.0.0.0 allows attackers to perform arbitrary port read and write actions via supplying crafted IOCTL requests.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-01-06T00:00:00

Updated: 2025-01-07T16:04:37.215Z

Reserved: 2024-12-06T00:00:00

Link: CVE-2024-55407

cve-icon Vulnrichment

Updated: 2025-01-07T15:35:50.365Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-01-06T19:15:12.910

Modified: 2025-01-07T16:15:36.480

Link: CVE-2024-55407

cve-icon Redhat

No data.