Impact
EAZ EazyFix 12.9 has a missing cryptographic step that allows a security feature bypass related to disabling secure boot. This flaw enables an attacker to circumvent controls intended to protect the secure boot configuration, potentially allowing unauthorized changes to system settings or elevated privileges. The weakness is classified as CWE-325, indicating improper handling of authentication or cryptographic checks.
Affected Systems
The affected system is EazyFix 12.9 produced by eazsolution. No additional versions or products were listed as vulnerable.
Risk and Exploitability
The CVSS score of 6.0 indicates a medium severity impact. EPSS data is not available, so the likelihood of exploitation cannot be quantified, and the vulnerability is not currently listed in the CISA KEV catalog. The attack vector is not explicitly defined in the description, so it is inferred that at least local or privileged access is required to exploit the missing cryptographic step that controls secure boot disabling.
OpenCVE Enrichment