cbcvebase.
CVE-2019-14553
published 2020-11-23

CVE-2019-14553: Improper authentication in EDK II may allow a privileged user to potentially enable information disclosure via network access.

PriorityP424medium4.9CVSS 3.1
AVNACLPRHUINSUCHINAN
EPSS
1.37%
68.7th percentile
Improper authentication in EDK II may allow a privileged user to potentially enable information disclosure via network access.

Affected

5 ranges
VendorProductVersion rangeFixed in
debianedk2< edk2 0~20190828.37eef910-4 (bookworm)edk2 0~20190828.37eef910-4 (bookworm)
tianocoreedk2>= 0 < 0~20190828.37eef910-40~20190828.37eef910-4
tianocoreedk2>= 0 < 0~20190828.37eef910-40~20190828.37eef910-4
tianocoreedk2>= 0 < 0~20190828.37eef910-40~20190828.37eef910-4
tianocoreedk2>= 0 < 0~20190828.37eef910-40~20190828.37eef910-4

CVSS provenance

nvdv3.14.9MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv7.5HIGH
vendor_debian4.9LOW
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.