9.8

CVE-2023-39281

A stack buffer overflow vulnerability discovered in AsfSecureBootDxe in Insyde InsydeH2O with kernel 5.0 through 5.5 allows attackers to run arbitrary code execution during the DXE phase.

Data is provided by the National Vulnerability Database (NVD)
InsydeInsydeh2o Version05.45.24.0039
   IntelB760 Version-
   IntelC262 Version-
   IntelC266 Version-
   IntelCore I3-1305u Version-
   IntelCore I3-13100 Version-
   IntelCore I3-13100e Version-
   IntelCore I3-13100f Version-
   IntelCore I3-13100t Version-
   IntelCore I3-13100te Version-
   IntelCore I3-1315u Version-
   IntelCore I3-1315ue Version-
   IntelCore I3-1315ure Version-
   IntelCore I3-1320pe Version-
   IntelCore I3-1320pre Version-
   IntelCore I3-13300he Version-
   IntelCore I3-13300hre Version-
   IntelCore I5-1334u Version-
   IntelCore I5-1335u Version-
   IntelCore I5-1335ue Version-
   IntelCore I5-13400 Version-
   IntelCore I5-13400e Version-
   IntelCore I5-13400f Version-
   IntelCore I5-13400t Version-
   IntelCore I5-1340p Version-
   IntelCore I5-1340pe Version-
   IntelCore I5-13420h Version-
   IntelCore I5-13450hx Version-
   IntelCore I5-1345u Version-
   IntelCore I5-1345ue Version-
   IntelCore I5-1345ure Version-
   IntelCore I5-13500 Version-
   IntelCore I5-13500e Version-
   IntelCore I5-13500h Version-
   IntelCore I5-13500hx Version-
   IntelCore I5-13500t Version-
   IntelCore I5-13500te Version-
   IntelCore I5-13505h Version-
   IntelCore I5-1350p Version-
   IntelCore I5-1350pe Version-
   IntelCore I5-1350pre Version-
   IntelCore I5-13600 Version-
   IntelCore I5-13600h Version-
   IntelCore I5-13600he Version-
   IntelCore I5-13600hre Version-
   IntelCore I5-13600hx Version-
   IntelCore I5-13600k Version-
   IntelCore I5-13600kf Version-
   IntelCore I5-13600t Version-
   IntelCore I5 14600k Version-
   IntelCore I5 14600kf Version-
   IntelCore I7-1355u Version-
   IntelCore I7-1360p Version-
   IntelCore I7-13620h Version-
   IntelCore I7-13650hx Version-
   IntelCore I7-1365u Version-
   IntelCore I7-1365ue Version-
   IntelCore I7-1365ure Version-
   IntelCore I7-1366ure Version-
   IntelCore I7-13700 Version-
   IntelCore I7-13700e Version-
   IntelCore I7-13700f Version-
   IntelCore I7-13700h Version-
   IntelCore I7-13700hx Version-
   IntelCore I7-13700k Version-
   IntelCore I7-13700kf Version-
   IntelCore I7-13700t Version-
   IntelCore I7-13700te Version-
   IntelCore I7-13705h Version-
   IntelCore I7-1370p Version-
   IntelCore I7-1370pe Version-
   IntelCore I7-1370pre Version-
   IntelCore I7-1375pre Version-
   IntelCore I7-13800h Version-
   IntelCore I7-13800he Version-
   IntelCore I7-13800hre Version-
   IntelCore I7-13850hx Version-
   IntelCore I7 14700k Version-
   IntelCore I7 14700kf Version-
   IntelCore I9-13900 Version-
   IntelCore I9-13900e Version-
   IntelCore I9-13900f Version-
   IntelCore I9-13900h Version-
   IntelCore I9-13900hk Version-
   IntelCore I9-13900hx Version-
   IntelCore I9-13900k Version-
   IntelCore I9-13900kf Version-
   IntelCore I9-13900ks Version-
   IntelCore I9-13900t Version-
   IntelCore I9-13900te Version-
   IntelCore I9-13905h Version-
   IntelCore I9-13950hx Version-
   IntelCore I9-13980hx Version-
   IntelCore I9-14900k Version-
   IntelCore I9-14900kf Version-
   IntelH770 Version-
   IntelHm770 Version-
   IntelU300 Version-
   IntelU300e Version-
   IntelWm790 Version-
   IntelZ790 Version-
InsydeInsydeh2o Version05.44.45.0017
   IntelAtom X7211e Version-
   IntelAtom X7213e Version-
   IntelAtom X7425e Version-
   IntelCore I3-n300 Version-
   IntelCore I3-n305 Version-
   IntelN100 Version-
   IntelN200 Version-
   IntelN50 Version-
   IntelN95 Version-
   IntelN97 Version-
InsydeInsydeh2o Version05.44.34.0055
   IntelCeleron 7300 Version-
   IntelCeleron 7305 Version-
   IntelCeleron G6900 Version-
   IntelCeleron G6900t Version-
   IntelCore I3-12100 Version-
   IntelCore I3-12100f Version-
   IntelCore I3-12100t Version-
   IntelCore I3-1210u Version-
   IntelCore I3-1215u Version-
   IntelCore I3-1220p Version-
   IntelCore I3-12300 Version-
   IntelCore I3-12300t Version-
   IntelCore I5-1230u Version-
   IntelCore I5-1235u Version-
   IntelCore I5-12400 Version-
   IntelCore I5-12400f Version-
   IntelCore I5-12400t Version-
   IntelCore I5-1240p Version-
   IntelCore I5-1240u Version-
   IntelCore I5-12450h Version-
   IntelCore I5-12450hx Version-
   IntelCore I5-1245u Version-
   IntelCore I5-12490f Version-
   IntelCore I5-12500 Version-
   IntelCore I5-12500h Version-
   IntelCore I5-12500t Version-
   IntelCore I5-1250p Version-
   IntelCore I5-12600 Version-
   IntelCore I5-12600h Version-
   IntelCore I5-12600hx Version-
   IntelCore I5-12600k Version-
   IntelCore I5-12600kf Version-
   IntelCore I5-12600t Version-
   IntelCore I7-1250u Version-
   IntelCore I7-1255u Version-
   IntelCore I7-1260p Version-
   IntelCore I7-1260u Version-
   IntelCore I7-12650h Version-
   IntelCore I7-12650hx Version-
   IntelCore I7-1265u Version-
   IntelCore I7-12700 Version-
   IntelCore I7-12700f Version-
   IntelCore I7-12700h Version-
   IntelCore I7-12700k Version-
   IntelCore I7-12700kf Version-
   IntelCore I7-12700t Version-
   IntelCore I7-1270p Version-
   IntelCore I7-12800h Version-
   IntelCore I7-12800hx Version-
   IntelCore I7-1280p Version-
   IntelCore I7-12850hx Version-
   IntelCore I9-12900 Version-
   IntelCore I9-12900f Version-
   IntelCore I9-12900h Version-
   IntelCore I9-12900hk Version-
   IntelCore I9-12900hx Version-
   IntelCore I9-12900k Version-
   IntelCore I9-12900kf Version-
   IntelCore I9-12900ks Version-
   IntelCore I9-12900t Version-
   IntelCore I9-12950hx Version-
   IntelPentium 8500 Version-
   IntelPentium 8505 Version-
   IntelPentium Gold G7400 Version-
   IntelPentium Gold G7400t Version-
InsydeInsydeh2o Version05.53.28.0013
   AmdRyzen 3 7335u Version-
   AmdRyzen 3 7440u Version-
   AmdRyzen 5 6600h Version-
   AmdRyzen 5 6600hs Version-
   AmdRyzen 5 6600u Version-
   AmdRyzen 5 7535hs Version-
   AmdRyzen 5 7535u Version-
   AmdRyzen 5 7540u Version-
   AmdRyzen 5 7545u Version-
   AmdRyzen 5 7640h Version-
   AmdRyzen 5 7640u Version-
   AmdRyzen 5 Pro 7640hs Version-
   AmdRyzen 7 6800h Version-
   AmdRyzen 7 6800hs Version-
   AmdRyzen 7 6800u Version-
   AmdRyzen 7 7735hs Version-
   AmdRyzen 7 7735u Version-
   AmdRyzen 7 7736u Version-
   AmdRyzen 7 7840h Version-
   AmdRyzen 7 7840u Version-
   AmdRyzen 7 Pro 7840hs Version-
   AmdRyzen 9 6900hs Version-
   AmdRyzen 9 6900hx Version-
   AmdRyzen 9 6980hs Version-
   AmdRyzen 9 6980hx Version-
   AmdRyzen 9 7940h Version-
   AmdRyzen 9 7940hs Version-
   AmdRyzen 9 Pro 7940hs Version-
   AmdRyzen Z1 Version-
   AmdRyzen Z1 Extreme Version-
   AmdV314 Version-
   AmdV3c16 Version-
   AmdV3c18 Version-
   AmdV3c44 Version-
   AmdV3c48 Version-
InsydeInsydeh2o Version05.45.38.0005
   IntelCeleron 7305l Version-
   IntelCore I3-1215ul Version-
   IntelCore I3-12300hl Version-
   IntelCore I5-1235ul Version-
   IntelCore I5-1245ul Version-
   IntelCore I5-12500hl Version-
   IntelCore I5-12600hl Version-
   IntelCore I7-1255ul Version-
   IntelCore I7-1265ul Version-
   IntelCore I7-12700hl Version-
   IntelCore I7-12800hl Version-
InsydeInsydeh2o Version05.53.23.0011
   AmdRyzen 7 7645hx Version-
   AmdRyzen 7 7745hx Version-
   AmdRyzen 7 7840hx Version-
   AmdRyzen 9 7645hx3d Version-
   AmdRyzen 9 7845hx Version-
   AmdRyzen 9 7940hx Version-
   AmdRyzen 9 7945hx Version-
InsydeInsydeh2o Version05.53.23.0014
   AmdAthlon Gold 7220u Version-
   AmdAthlon Silver 7120u Version-
   AmdRyzen 3 7320u Version-
   AmdRyzen 5 7520u Version-
InsydeInsydeh2o Version05.53.22.0008
   AmdRyzen 5 7500f Version-
   AmdRyzen 5 7600 Version-
   AmdRyzen 5 7600x Version-
   AmdRyzen 5 Pro 7645 Version-
   AmdRyzen 7 7700 Version-
   AmdRyzen 7 7700x Version-
   AmdRyzen 7 7800x3d Version-
   AmdRyzen 7 Pro 7745 Version-
   AmdRyzen 9 7900 Version-
   AmdRyzen 9 7900x Version-
   AmdRyzen 9 7900x3d Version-
   AmdRyzen 9 7950x Version-
   AmdRyzen 9 7950x3d Version-
   AmdRyzen 9 Pro 7945 Version-
InsydeInsydeh2o Version05.44.30.0022
   AmdRyzen 3 7335u Version-
   AmdRyzen 5 6600h Version-
   AmdRyzen 5 6600hs Version-
   AmdRyzen 5 6600u Version-
   AmdRyzen 5 7535hs Version-
   AmdRyzen 5 7535u Version-
   AmdRyzen 7 6800h Version-
   AmdRyzen 7 6800hs Version-
   AmdRyzen 7 6800u Version-
   AmdRyzen 7 7735hs Version-
   AmdRyzen 7 7735u Version-
   AmdRyzen 7 7736u Version-
   AmdRyzen 9 6900hs Version-
   AmdRyzen 9 6900hx Version-
   AmdRyzen 9 6980hs Version-
   AmdRyzen 9 6980hx Version-
InsydeInsydeh2o Version05.43.06.0021
   AmdVan Gogh 0405 Version-
InsydeInsydeh2o Version05.42.37.0031
   AmdRyzen 3 5100 Version-
   AmdRyzen 3 5125c Version-
   AmdRyzen 3 5300g Version-
   AmdRyzen 3 5300ge Version-
   AmdRyzen 3 5400u Version-
   AmdRyzen 3 5425u Version-
   AmdRyzen 3 Pro 7330u Version-
   AmdRyzen 5 5500 Version-
   AmdRyzen 5 5500h Version-
   AmdRyzen 5 5500u Version-
   AmdRyzen 5 5560u Version-
   AmdRyzen 5 5600g Version-
   AmdRyzen 5 5600ge Version-
   AmdRyzen 5 5600h Version-
   AmdRyzen 5 5600hs Version-
   AmdRyzen 5 5600u Version-
   AmdRyzen 5 5625u Version-
   AmdRyzen 5 Pro 7530u Version-
   AmdRyzen 7 5700 Version-
   AmdRyzen 7 5700g Version-
   AmdRyzen 7 5700ge Version-
   AmdRyzen 7 5700u Version-
   AmdRyzen 7 5800h Version-
   AmdRyzen 7 5800hs Version-
   AmdRyzen 7 5800u Version-
   AmdRyzen 7 5825u Version-
   AmdRyzen 7 Pro 7730u Version-
   AmdRyzen 9 5900hs Version-
   AmdRyzen 9 5900hx Version-
   AmdRyzen 9 5980hs Version-
   AmdRyzen3 5300u Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.23% 0.459
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
134c704f-9b21-4f2e-91b3-4a467353bcc0 5.7 0.5 5.2
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N
CWE-121 Stack-based Buffer Overflow

A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.