Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-35896


An issue SMM memory leak vulnerability in SMM driver (SMRAM was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. An attacker can dump SMRAM contents via the software SMI provided by the FvbServicesRuntimeDxe driver to read the contents of SMRAM, leading to information disclosure.


Published

2022-09-22T00:15:10.003

Last Modified

2025-05-05T17:18:17.600

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.0 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-20
  • Type: Secondary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application insyde insydeh2o ≤ 5.5 Yes

References