Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-25600


An issue was discovered in InsydeH2O. A malicious operating system can tamper with a runtime-writable EFI variable, leading to out-of-bounds memory reads and a denial of service. This is fixed in version 01.01.04.0016.


Published

2023-08-03T15:15:19.340

Last Modified

2024-11-21T07:49:48.400

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.1 (HIGH)

Weaknesses
  • Type: Primary
    CWE-125

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application insyde insydecrpkg < 01.01.04.0016 Yes

References