Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-31041


An issue was discovered in SysPasswordDxe in Insyde InsydeH2O with kernel 5.0 through 5.5. System password information could optionally be stored in cleartext, which might lead to possible information disclosure.


Published

2023-08-14T15:15:12.237

Last Modified

2024-11-21T08:01:18.313

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Primary
    CWE-312

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application insyde insydeh2o 5.0 Yes
Application insyde insydeh2o 5.1 Yes
Application insyde insydeh2o 5.2 Yes
Application insyde insydeh2o 5.3 Yes
Application insyde insydeh2o 5.4 Yes
Application insyde insydeh2o 5.5 Yes

References