CWE-1190: DMA Device Enabled Too Early in Boot Phase

low-risk

The product enables a Direct Memory Access (DMA) capable device before the security configuration settings are established, which allows an attacker to extract data from or gain privileges on the product.

Abstraction: Base

Common Consequences

Access Control Bypass Protection Mechanism

Real-World Examples (1)

CVE CVSS EPSS KEV
CVE-2022-22566 6.9 0.0%
0
/ 100
low-risk
Active Threat 0/50 · Minimal
Exploit Availability 0/50 · Minimal