CVE-2023-27373
- EPSS 0.05%
- Veröffentlicht 07.08.2023 15:15:10
- Zuletzt bearbeitet 07.03.2025 20:15:36
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. Due to insufficient input validation, an attacker can tamper with a runtime-accessible EFI variable to cause a dynamic BAR setting to overlap SMRAM.
CVE-2023-22616
- EPSS 0.06%
- Veröffentlicht 12.04.2023 13:15:07
- Zuletzt bearbeitet 10.02.2025 17:15:16
An issue was discovered in Insyde InsydeH2O with kernel 5.2 through 5.5. The Save State register is not checked before use. The IhisiSmm driver does not check the value of a save state register before use. Due to insufficient input validation, an att...
CVE-2022-24350
- EPSS 0.04%
- Veröffentlicht 12.04.2023 13:15:07
- Zuletzt bearbeitet 19.03.2025 16:15:15
An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. IHISI function 0x17 verifies that the output buffer lies within the command buffer but does not verify that output data does not go beyond the end of the command buf...
CVE-2023-22613
- EPSS 0.07%
- Veröffentlicht 11.04.2023 22:15:07
- Zuletzt bearbeitet 11.02.2025 20:15:31
An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. It is possible to write to an attacker-controlled address. An attacker could invoke an SMI handler with a malformed pointer in RCX that overlaps SMRAM, resulting in ...
CVE-2023-22615
- EPSS 0.22%
- Veröffentlicht 11.04.2023 21:15:17
- Zuletzt bearbeitet 11.02.2025 21:15:10
An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. IHISI subfunction execution may corrupt SMRAM. An attacker can pass an address in the RCX save state register that overlaps SMRAM, thereby coercing an IHISI subfunct...
CVE-2023-22614
- EPSS 0.15%
- Veröffentlicht 11.04.2023 21:15:17
- Zuletzt bearbeitet 11.02.2025 20:15:31
An issue was discovered in ChipsetSvcSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. There is insufficient input validation in BIOS Guard updates. An attacker can induce memory corruption in SMM by supplying malformed inputs to the BIOS Guard SM...
CVE-2023-22612
- EPSS 0.17%
- Veröffentlicht 11.04.2023 21:15:17
- Zuletzt bearbeitet 11.02.2025 18:15:21
An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. A malicious host OS can invoke an Insyde SMI handler with malformed arguments, resulting in memory corruption in SMM.
- EPSS 0.05%
- Veröffentlicht 15.02.2023 14:15:12
- Zuletzt bearbeitet 05.05.2025 17:18:14
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the FvbServicesRuntimeDxe shared buffer used by SMM and non-SMM code could cause TOCTOU race-condition issues that could lead to corruption of SMRAM and escalatio...
- EPSS 0.05%
- Veröffentlicht 15.02.2023 14:15:11
- Zuletzt bearbeitet 05.05.2025 17:18:13
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the PnpSmm shared buffer used by SMM and non-SMM code could cause TOCTOU race-condition issues that could lead to corruption of SMRAM and escalation of privileges...
- EPSS 0.05%
- Veröffentlicht 15.02.2023 14:15:11
- Zuletzt bearbeitet 05.05.2025 17:18:14
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the VariableRuntimeDxe shared buffer used by SMM and non-SMM code could cause TOCTOU race-condition issues that could lead to corruption of SMRAM and escalation o...