Insyde

Insydeh2o

84 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.14%
  • Veröffentlicht 19.10.2023 20:15:08
  • Zuletzt bearbeitet 21.11.2024 08:00:33

An issue was discovered in TrEEConfigDriver in Insyde InsydeH2O with kernel 5.0 through 5.5. It can report false TPM PCR values, and thus mask malware activity. Devices use Platform Configuration Registers (PCRs) to record information about device an...

  • EPSS 0.09%
  • Veröffentlicht 18.09.2023 13:15:08
  • Zuletzt bearbeitet 21.11.2024 08:06:45

An issue was discovered in SystemFirmwareManagementRuntimeDxe in Insyde InsydeH2O with kernel 5.0 through 5.5. The implementation of the GetImage method retrieves the value of a runtime variable named GetImageProgress, and later uses this value as a ...

  • EPSS 0.04%
  • Veröffentlicht 18.08.2023 19:15:12
  • Zuletzt bearbeitet 21.11.2024 07:52:58

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. UEFI implementations do not correctly protect and validate information contained in the 'MeSetup' UEFI variable. On some systems, this variable can be overwritten using operatin...

  • EPSS 0.11%
  • Veröffentlicht 14.08.2023 15:15:12
  • Zuletzt bearbeitet 21.11.2024 08:01:18

An issue was discovered in SysPasswordDxe in Insyde InsydeH2O with kernel 5.0 through 5.5. System password information could optionally be stored in cleartext, which might lead to possible information disclosure.

  • EPSS 0.06%
  • Veröffentlicht 07.08.2023 15:15:10
  • Zuletzt bearbeitet 07.03.2025 20:15:36

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. Due to insufficient input validation, an attacker can tamper with a runtime-accessible EFI variable to cause a dynamic BAR setting to overlap SMRAM.

Exploit
  • EPSS 0.07%
  • Veröffentlicht 12.04.2023 13:15:07
  • Zuletzt bearbeitet 10.02.2025 17:15:16

An issue was discovered in Insyde InsydeH2O with kernel 5.2 through 5.5. The Save State register is not checked before use. The IhisiSmm driver does not check the value of a save state register before use. Due to insufficient input validation, an att...

  • EPSS 0.05%
  • Veröffentlicht 12.04.2023 13:15:07
  • Zuletzt bearbeitet 19.03.2025 16:15:15

An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. IHISI function 0x17 verifies that the output buffer lies within the command buffer but does not verify that output data does not go beyond the end of the command buf...

  • EPSS 0.08%
  • Veröffentlicht 11.04.2023 22:15:07
  • Zuletzt bearbeitet 11.02.2025 20:15:31

An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. It is possible to write to an attacker-controlled address. An attacker could invoke an SMI handler with a malformed pointer in RCX that overlaps SMRAM, resulting in ...

  • EPSS 0.24%
  • Veröffentlicht 11.04.2023 21:15:17
  • Zuletzt bearbeitet 11.02.2025 21:15:10

An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. IHISI subfunction execution may corrupt SMRAM. An attacker can pass an address in the RCX save state register that overlaps SMRAM, thereby coercing an IHISI subfunct...

Exploit
  • EPSS 0.17%
  • Veröffentlicht 11.04.2023 21:15:17
  • Zuletzt bearbeitet 11.02.2025 20:15:31

An issue was discovered in ChipsetSvcSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. There is insufficient input validation in BIOS Guard updates. An attacker can induce memory corruption in SMM by supplying malformed inputs to the BIOS Guard SM...