VYPR

CWE-1190

DMA Device Enabled Too Early in Boot Phase

BaseDraft

Description

The product enables a Direct Memory Access (DMA) capable device before the security configuration settings are established, which allows an attacker to extract data from or gain privileges on the product.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-180

CVEs mapped to this weakness (2)

  • CVE-2026-28653HigSep 8, 2026
    risk 0.51cvss 7.8epss 0.00

    In multiple functions of rw_t3t.cc, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2022-22566MedFeb 9, 2022
    risk 0.45cvss 6.9epss 0.00

    Select Dell Client Commercial and Consumer platforms contain a pre-boot direct memory access (DMA) vulnerability. An authenticated attacker with physical access to the system may potentially exploit this vulnerability in order to execute arbitrary code on the device.