CVE-2024-55408

MEDIUM

ASUS ASCI - Missing Authorization via Crafted IOCTL Requests

Title source: llm
STIX 2.1

Description

An improper access control vulnerability in the AsusSAIO.sys driver may lead to the misuse of software functionality utilizing the driver when crafted IOCTL requests are supplied.

Scores

CVSS v3 5.3
EPSS 0.0012
EPSS Percentile 30.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (2)
ASUS/ASCI before 1.0.30.0
ASUS/ASCI before 3.1.41.0
Published Jan 06, 2025
Tracked Since Feb 18, 2026