An improper access control vulnerability in the AsusSAIO.sys driver may lead to the misuse of software functionality utilizing the driver when crafted IOCTL requests are supplied.
History

Tue, 11 Feb 2025 01:00:00 +0000

Type Values Removed Values Added
Description An issue in the AsusSAIO.sys component of ASUS System Analysis IO v1.0.0 allows attackers to perform arbitrary read and write actions via supplying crafted IOCTL requests. An improper access control vulnerability in the AsusSAIO.sys driver may lead to the misuse of software functionality utilizing the driver when crafted IOCTL requests are supplied.
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


Tue, 07 Jan 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 06 Jan 2025 19:00:00 +0000

Type Values Removed Values Added
Description An issue in the AsusSAIO.sys component of ASUS System Analysis IO v1.0.0 allows attackers to perform arbitrary read and write actions via supplying crafted IOCTL requests.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-01-06T00:00:00

Updated: 2025-02-11T00:54:34.836Z

Reserved: 2024-12-06T00:00:00

Link: CVE-2024-55408

cve-icon Vulnrichment

Updated: 2025-01-07T21:55:31.119Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-01-06T19:15:13.010

Modified: 2025-02-11T01:15:09.410

Link: CVE-2024-55408

cve-icon Redhat

No data.