8.2

CVE-2022-35895

Exploit

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. The FwBlockSericceSmm driver does not properly validate input parameters for a software SMI routine, leading to memory corruption of arbitrary addresses including SMRAM, and possible arbitrary code execution.

Data is provided by the National Vulnerability Database (NVD)
InsydeInsydeh2o Version >= 5.0 < 05.09.37
InsydeInsydeh2o Version >= 5.1 < 05.17.37
InsydeInsydeh2o Version >= 5.2 < 05.27.29
InsydeInsydeh2o Version >= 5.3 < 05.36.29
InsydeInsydeh2o Version >= 5.4 < 05.44.29
InsydeInsydeh2o Version >= 5.5 < 05.52.29
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.07% 0.221
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.2 1.5 6
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
134c704f-9b21-4f2e-91b3-4a467353bcc0 8.2 1.5 6
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.