Impact
Exposed IOCTL in the Asus Armoury Crate driver enables a local user to read and write PCIe configuration space because the driver does not enforce proper authentication. The flaw falls under CWE-782 and allows sensitive information disclosure and disruption of device functionality by disabling the device.
Affected Systems
ASUS Armoury Crate, all versions for which a fix is not yet applied. Updated releases should be checked against the latest advisory.
Risk and Exploitability
The CVSS score of 5.9 indicates a moderate risk; the EPSS score is not available and the vulnerability is not listed in CISA KEV. Attackers would need local access to the system to interact with the vulnerable driver, so the vector is local. If compromised, the attacker could read hidden configuration data and potentially disable the device.
OpenCVE Enrichment