{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.1",
    "cveMetadata": {
        "cveId": "CVE-2024-2207",
        "assignerOrgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
        "state": "PUBLISHED",
        "assignerShortName": "hp",
        "dateReserved": "2024-03-05T22:33:59.358Z",
        "datePublished": "2024-11-12T19:24:46.327Z",
        "dateUpdated": "2024-11-13T18:26:16.314Z"
    },
    "containers": {
        "cna": {
            "affected": [
                {
                    "defaultStatus": "unknown",
                    "product": "SECOMN64 Driver",
                    "vendor": "Sound Research",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "See HP Security Bulletin reference for affected versions."
                        }
                    ]
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "supportingMedia": [
                        {
                            "base64": false,
                            "type": "text/html",
                            "value": "<span style=\"background-color: rgb(255, 255, 255);\">Potential vulnerabilities have been identified in the audio package for certain HP PC products using the Sound Research SECOMN64 driver, which might allow escalation of privilege. Sound Research has released driver updates to mitigate the potential vulnerabilities.</span>"
                        }
                    ],
                    "value": "Potential vulnerabilities have been identified in the audio package for certain HP PC products using the Sound Research SECOMN64 driver, which might allow escalation of privilege. Sound Research has released driver updates to mitigate the potential vulnerabilities."
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "attackComplexity": "HIGH",
                        "attackVector": "LOCAL",
                        "availabilityImpact": "HIGH",
                        "baseScore": 6,
                        "baseSeverity": "MEDIUM",
                        "confidentialityImpact": "LOW",
                        "integrityImpact": "HIGH",
                        "privilegesRequired": "HIGH",
                        "scope": "UNCHANGED",
                        "userInteraction": "NONE",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:H/A:H",
                        "version": "3.1"
                    },
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ]
                }
            ],
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "cweId": "CWE-427",
                            "description": "CWE-427 Uncontrolled Search Path Element",
                            "lang": "en",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "providerMetadata": {
                "orgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
                "shortName": "hp",
                "dateUpdated": "2024-11-12T19:24:46.327Z"
            },
            "references": [
                {
                    "url": "https://support.hp.com/us-en/document/ish_11567250-11567490-16/hpsbhf03987"
                }
            ],
            "source": {
                "discovery": "UNKNOWN"
            },
            "title": "Sound Research SECOMN64 Escalation of Privilege",
            "x_generator": {
                "engine": "Vulnogram 0.2.0"
            }
        },
        "adp": [
            {
                "affected": [
                    {
                        "vendor": "hewlett_packard_enterprise",
                        "product": "sound_research_secomn64_driver",
                        "cpes": [
                            "cpe:2.3:a:hewlett_packard_enterprise:sound_research_secomn64_driver:*:*:*:*:*:*:*:*"
                        ],
                        "defaultStatus": "unknown",
                        "versions": [
                            {
                                "version": "1",
                                "status": "affected"
                            }
                        ]
                    }
                ],
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2024-11-13T18:24:18.622087Z",
                                "id": "CVE-2024-2207",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "total"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2024-11-13T18:26:16.314Z"
                }
            }
        ]
    }
}