cbcvebase.
CVE-2019-14553
published 2020-11-23

CVE-2019-14553: Improper authentication in EDK II may allow a privileged user to potentially enable information disclosure via network access.

medium4.9CVSS 3.1
AVNACLPRHUINSUCHINAN
Improper authentication in EDK II may allow a privileged user to potentially enable information disclosure via network access.

Affected

5 ranges
VendorProductVersion rangeFixed in
debianedk2< edk2 0~20190828.37eef910-4 (bookworm)edk2 0~20190828.37eef910-4 (bookworm)
tianocoreedk2>= 0 < 0~20190828.37eef910-40~20190828.37eef910-4
tianocoreedk2>= 0 < 0~20190828.37eef910-40~20190828.37eef910-4
tianocoreedk2>= 0 < 0~20190828.37eef910-40~20190828.37eef910-4
tianocoreedk2>= 0 < 0~20190828.37eef910-40~20190828.37eef910-4

CVSS provenance

nvdv3.14.9MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
osv7.5HIGH