CVE-2020-13510 is an information disclosure vulnerability affecting NZXT CAM 4.8.0, specifically within the WinRing0x64 Driver's Privileged I/O Read IRPs functionality. A low-privileged attacker can craft a malicious I/O request packet (IRP 0x9c4060d0) to gain direct, unrestrained access to the IN instruction at an elevated privilege level. Rated Medium (CVSS 6.5), this local attack requires low privileges and user interaction is not required, leading to high confidentiality impact but no integrity or availability impact. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.8.0CPE matchmatch criteria | cpe:2.3:a:nzxt:cam:4.8.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.