CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 6.8. See the original NVD description below for full technical details.
CVE
CVE-2014-4860
Severity
MEDIUM
CVSS
6.8
EPSS
0.50%
Original NVD Description
Multiple integer overflows in the Pre-EFI Initialization (PEI) boot phase in the Capsule Update feature in the UEFI implementation in EDK2 allow physically proximate attackers to bypass intended access restrictions by providing crafted data that is not properly handled during the coalescing phase.
Related CVEs
Other vulnerabilities affecting the same vendor(s)