Impact
This vulnerability is an out‑of‑bounds read (CWE‑125) that allows a local administrator to read memory regions beyond the intended firmware boundary by sending a crafted IOCTL request to the ASUS System Control Interface v3 or the Business Manager. The read can expose sensitive data that the firmware was designed to protect, potentially exposing confidential information held by the device.
Affected Systems
ASUS Business Manager, ASUS System Control Interface, and the v3 iteration of the System Control Interface are affected. No specific firmware or hardware revision numbers are provided, so any current installation of these components is considered vulnerable. The issue is limited to devices running the impacted ASUS firmware modules.
Risk and Exploitability
The CVSS score of 5.6 marks this as a moderate‑severity local disclosure. The EPSS score of less than 1% indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, implying no known widespread active attacks. Exploitation requires local administrative access to the device and the ability to send a crafted IOCTL request to the vulnerable driver.
OpenCVE Enrichment