Description
Out-of-bounds Read in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to read memory regions beyond the intended firmware boundary by supplying a crafted IOCTL request that bypasses the validation.
Refer to the ' Security Update for ASUS System Control Interface  ' section on the ASUS Security Advisory for more information.
Published: 2026-07-15
Score: 5.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is an out‑of‑bounds read (CWE‑125) that allows a local administrator to read memory regions beyond the intended firmware boundary by sending a crafted IOCTL request to the ASUS System Control Interface v3 or the Business Manager. The read can expose sensitive data that the firmware was designed to protect, potentially exposing confidential information held by the device.

Affected Systems

ASUS Business Manager, ASUS System Control Interface, and the v3 iteration of the System Control Interface are affected. No specific firmware or hardware revision numbers are provided, so any current installation of these components is considered vulnerable. The issue is limited to devices running the impacted ASUS firmware modules.

Risk and Exploitability

The CVSS score of 5.6 marks this as a moderate‑severity local disclosure. The EPSS score of less than 1% indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, implying no known widespread active attacks. Exploitation requires local administrative access to the device and the ability to send a crafted IOCTL request to the vulnerable driver.

Generated by OpenCVE AI on August 1, 2026 at 09:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the latest security update for ASUS System Control Interface and Business Manager as released by ASUS.
  • Configure the system to restrict the vulnerable IOCTL so that it can only be accessed by trusted applications or requires higher‑level authentication.
  • Apply least‑privilege principles by limiting local administrator accounts to personnel who absolutely need them.

Generated by OpenCVE AI on August 1, 2026 at 09:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Sat, 01 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
Title Local Out‑of‑Bounds Read via Crafted IOCTL in ASUS System Control Interface

Tue, 28 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Local Administrator Out-of-Bounds Read in ASUS System Control Interface

Wed, 22 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Local Administrator Out-of-Bounds Read in ASUS System Control Interface

Fri, 17 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in ASUS System Control Interface Leading to Local Memory Disclosure

Thu, 16 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in ASUS System Control Interface Leading to Local Memory Disclosure

Wed, 15 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Description Out-of-bounds Read in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to read memory regions beyond the intended firmware boundary by supplying a crafted IOCTL request that bypasses the validation. Refer to the ' Security Update for ASUS System Control Interface  ' section on the ASUS Security Advisory for more information.
First Time appeared Asus
Asus business Manager
Asus system Control Interface
Asus system Control Interface V3
Weaknesses CWE-125
CPEs cpe:2.3:a:asus:business_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:asus:system_control_interface:*:*:*:*:*:*:*:*
cpe:2.3:a:asus:system_control_interface_v3:*:*:*:*:*:*:*:*
Vendors & Products Asus
Asus business Manager
Asus system Control Interface
Asus system Control Interface V3
References
Metrics cvssV4_0

{'score': 5.6, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Asus Business Manager System Control Interface System Control Interface V3
cve-icon MITRE

Status: PUBLISHED

Assigner: ASUS

Published:

Updated: 2026-07-15T14:24:06.901Z

Reserved: 2026-07-08T07:18:46.459Z

Link: CVE-2026-15030

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T09:15:03Z

Weaknesses