CVE-2020-15596

MEDIUMCVSS 6.7/10EPSS 0.43%

Last modified

CVE-2020-15596 is a medium-severity vulnerability rated 6.7/10 on the CVSS scale. The ALPS ALPINE touchpad driver before 8.2206.1717.634, as used on various Dell, HP, and Lenovo laptops, allows attackers to conduct Path Disclosure attacks via a "fake" DLL file.. EPSS estimates a 0.43% chance of exploitation in the next 30 days.

Description

The ALPS ALPINE touchpad driver before 8.2206.1717.634, as used on various Dell, HP, and Lenovo laptops, allows attackers to conduct Path Disclosure attacks via a "fake" DLL file.

Metrics

CVSS 3.1
6.7/10

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.43%

34.2th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
HpElite X2 1012 G1 Firmware< 8.2206.1717.166
HpElite X2 1012 G2 Firmware< 8.2206.1717.634
HpElitebook 1030 G1 Firmware< 8.2206.1717.166
HpElitebook 1040 G4 Firmware< 8.2206.1717.634
HpElitebook Folio 1040 G3 Firmware< 8.2206.1717.166
HpElitebook Folio G1 Firmware< 8.2206.1717.166
HpElitebook Revolve 810 G2 Firmware< 10.1201.1717.108
HpElitebook Revolve 810 G3 Firmware< 10.1201.1717.108
HpElitebook X360 1020 G2 Firmware< 8.2206.1717.634
HpElitebook X360 1030 G2 Firmware< 8.2206.1717.634
HpPro X2 612 G2 Firmware< 8.2206.1717.634
HpZbook Studio G3 Firmware< 8.2206.1717.166
HpZbook Studio G4 Firmware< 8.2206.1717.634
HpZbook X2 G4 Firmware< 8.2206.1717.634

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-15596?
The ALPS ALPINE touchpad driver before 8.2206.1717.634, as used on various Dell, HP, and Lenovo laptops, allows attackers to conduct Path Disclosure attacks via a "fake" DLL file.
How severe is CVE-2020-15596?
CVE-2020-15596 has a CVSS score of 6.7/10 (MEDIUM severity). The EPSS model estimates a 0.43% probability of exploitation in the next 30 days.
How do I fix CVE-2020-15596?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-15596?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST