Impact
An out‑of‑bounds write in the SmiFlash SMM module of the device’s BIOS allows a local administrator to send a crafted software SMI request with an oversized payload. This can result in a system crash (BSOD) or in the corruption of the BIOS firmware, compromising system integrity and availability. The vulnerability does not provide remote code execution or privilege escalation beyond the local administrator role.
Affected Systems
The flaw impacts ASUS FA507NU and ASUS FA507NV models running BIOS version 318.
Risk and Exploitability
The CVSS score of 6.8 places the issue in the "medium" severity range. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, indicating no known widespread exploitation yet. Given that the attack requires local privileged access, the likelihood of exploitation is moderate and primarily limited to environments where system administrators have direct control of the hardware. As such, timely remediation through a BIOS update is strongly recommended to mitigate the risk.
OpenCVE Enrichment