The product enables a Direct Memory Access (DMA) capable device before the security configuration settings are established, which allows an attacker to extract data from or gain privileges on the product.
Extended description
Best practices to prevent this CWE
Phase: Architecture and Design
Utilize an IOMMU to orchestrate IO access from
the start of the boot process.