PT-2024-11951 · Asp+1 · Asp+1

Published

2024-08-13

·

Updated

2025-08-13

·

CVE-2023-20518

CVSS v3.1

1.9

Low

VectorAV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions ASP (affected versions not specified)
Description The issue is related to incomplete cleanup in the ASP, which may expose the Master Encryption Key (MEK) to a privileged attacker with access to the BIOS menu or UEFI shell and a memory exfiltration vulnerability, potentially resulting in loss of confidentiality.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2025-09856
CVE-2023-20518

Affected Products

Asp
Red Os