Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-35894


An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. The SMI handler for the FwBlockServiceSmm driver uses an untrusted pointer as the location to copy data to an attacker-specified buffer, leading to information disclosure.


Published

2022-09-22T18:15:10.200

Last Modified

2025-05-05T17:18:17.063

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.0 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-401
  • Type: Secondary
    CWE-401

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application insyde insydeh2o < 05.09.37 Yes
Application insyde insydeh2o < 5.17.37 Yes
Application insyde insydeh2o < 05.27.29 Yes
Application insyde insydeh2o < 05.36.29 Yes
Application insyde insydeh2o < 05.44.29 Yes
Application insyde insydeh2o < 05.52.29 Yes

References