VYPR

CWE-1190

DMA Device Enabled Too Early in Boot Phase

BaseDraft

Description

The product enables a Direct Memory Access (DMA) capable device before the security configuration settings are established, which allows an attacker to extract data from or gain privileges on the product.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-180

CVEs mapped to this weakness (1)

  • CVE-2022-22566MedFeb 9, 2022
    risk 0.45cvss 6.9epss 0.00

    Select Dell Client Commercial and Consumer platforms contain a pre-boot direct memory access (DMA) vulnerability. An authenticated attacker with physical access to the system may potentially exploit this vulnerability in order to execute arbitrary code on the device.