Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-39281


A stack buffer overflow vulnerability discovered in AsfSecureBootDxe in Insyde InsydeH2O with kernel 5.0 through 5.5 allows attackers to run arbitrary code execution during the DXE phase.


Security Impact Summary

This vulnerability carries a CRITICAL severity rating with a CVSS v3.1 score of 9.8, indicating it can be exploited remotely over the network with relatively low complexity without requiring user interaction and does not require pre-existing privileges . The vulnerability impacts confidentiality (data exposure), integrity (unauthorized modifications), and availability (service disruption) for affected systems. Impacting 279 products from insyde, from intel, from intel and 276 others, organizations running these solutions should prioritize assessment and patching.

Historical Context

Reported in 2023, this vulnerability emerged during an era marked by increased sophistication in supply chain attacks, cloud infrastructure vulnerabilities, and software-as-a-service (SaaS) security challenges. Security practices during this period emphasized zero-trust architectures, container security, and API protection.


Published

2023-11-01T22:15:08.547

Last Modified

2024-11-21T08:15:03.373

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-787
  • Type: Secondary
    CWE-121

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application insyde insydeh2o 05.45.24.0039 Yes
Hardware intel b760 - No
Hardware intel c262 - No
Hardware intel c266 - No
Hardware intel core_i3-1305u - No
Hardware intel core_i3-13100 - No
Hardware intel core_i3-13100e - No
Hardware intel core_i3-13100f - No
Hardware intel core_i3-13100t - No
Hardware intel core_i3-13100te - No
Hardware intel core_i3-1315u - No
Hardware intel core_i3-1315ue - No
Hardware intel core_i3-1315ure - No
Hardware intel core_i3-1320pe - No
Hardware intel core_i3-1320pre - No
Hardware intel core_i3-13300he - No
Hardware intel core_i3-13300hre - No
Hardware intel core_i5-1334u - No
Hardware intel core_i5-1335u - No
Hardware intel core_i5-1335ue - No
Hardware intel core_i5-13400 - No
Hardware intel core_i5-13400e - No
Hardware intel core_i5-13400f - No
Hardware intel core_i5-13400t - No
Hardware intel core_i5-1340p - No
Hardware intel core_i5-1340pe - No
Hardware intel core_i5-13420h - No
Hardware intel core_i5-13450hx - No
Hardware intel core_i5-1345u - No
Hardware intel core_i5-1345ue - No
Hardware intel core_i5-1345ure - No
Hardware intel core_i5-13500 - No
Hardware intel core_i5-13500e - No
Hardware intel core_i5-13500h - No
Hardware intel core_i5-13500hx - No
Hardware intel core_i5-13500t - No
Hardware intel core_i5-13500te - No
Hardware intel core_i5-13505h - No
Hardware intel core_i5-1350p - No
Hardware intel core_i5-1350pe - No
Hardware intel core_i5-1350pre - No
Hardware intel core_i5-13600 - No
Hardware intel core_i5-13600h - No
Hardware intel core_i5-13600he - No
Hardware intel core_i5-13600hre - No
Hardware intel core_i5-13600hx - No
Hardware intel core_i5-13600k - No
Hardware intel core_i5-13600kf - No
Hardware intel core_i5-13600t - No
Hardware intel core_i5_14600k - No
Hardware intel core_i5_14600kf - No
Hardware intel core_i7-1355u - No
Hardware intel core_i7-1360p - No
Hardware intel core_i7-13620h - No
Hardware intel core_i7-13650hx - No
Hardware intel core_i7-1365u - No
Hardware intel core_i7-1365ue - No
Hardware intel core_i7-1365ure - No
Hardware intel core_i7-1366ure - No
Hardware intel core_i7-13700 - No
Hardware intel core_i7-13700e - No
Hardware intel core_i7-13700f - No
Hardware intel core_i7-13700h - No
Hardware intel core_i7-13700hx - No
Hardware intel core_i7-13700k - No
Hardware intel core_i7-13700kf - No
Hardware intel core_i7-13700t - No
Hardware intel core_i7-13700te - No
Hardware intel core_i7-13705h - No
Hardware intel core_i7-1370p - No
Hardware intel core_i7-1370pe - No
Hardware intel core_i7-1370pre - No
Hardware intel core_i7-1375pre - No
Hardware intel core_i7-13800h - No
Hardware intel core_i7-13800he - No
Hardware intel core_i7-13800hre - No
Hardware intel core_i7-13850hx - No
Hardware intel core_i7_14700k - No
Hardware intel core_i7_14700kf - No
Hardware intel core_i9-13900 - No
Hardware intel core_i9-13900e - No
Hardware intel core_i9-13900f - No
Hardware intel core_i9-13900h - No
Hardware intel core_i9-13900hk - No
Hardware intel core_i9-13900hx - No
Hardware intel core_i9-13900k - No
Hardware intel core_i9-13900kf - No
Hardware intel core_i9-13900ks - No
Hardware intel core_i9-13900t - No
Hardware intel core_i9-13900te - No
Hardware intel core_i9-13905h - No
Hardware intel core_i9-13950hx - No
Hardware intel core_i9-13980hx - No
Hardware intel core_i9-14900k - No
Hardware intel core_i9-14900kf - No
Hardware intel h770 - No
Hardware intel hm770 - No
Hardware intel u300 - No
Hardware intel u300e - No
Hardware intel wm790 - No
Hardware intel z790 - No
Application insyde insydeh2o 05.44.45.0017 Yes
Hardware intel atom_x7211e - No
Hardware intel atom_x7213e - No
Hardware intel atom_x7425e - No
Hardware intel core_i3-n300 - No
Hardware intel core_i3-n305 - No
Hardware intel n100 - No
Hardware intel n200 - No
Hardware intel n50 - No
Hardware intel n95 - No
Hardware intel n97 - No
Application insyde insydeh2o 05.44.34.0055 Yes
Hardware intel celeron_7300 - No
Hardware intel celeron_7305 - No
Hardware intel celeron_g6900 - No
Hardware intel celeron_g6900t - No
Hardware intel core_i3-12100 - No
Hardware intel core_i3-12100f - No
Hardware intel core_i3-12100t - No
Hardware intel core_i3-1210u - No
Hardware intel core_i3-1215u - No
Hardware intel core_i3-1220p - No
Hardware intel core_i3-12300 - No
Hardware intel core_i3-12300t - No
Hardware intel core_i5-1230u - No
Hardware intel core_i5-1235u - No
Hardware intel core_i5-12400 - No
Hardware intel core_i5-12400f - No
Hardware intel core_i5-12400t - No
Hardware intel core_i5-1240p - No
Hardware intel core_i5-1240u - No
Hardware intel core_i5-12450h - No
Hardware intel core_i5-12450hx - No
Hardware intel core_i5-1245u - No
Hardware intel core_i5-12490f - No
Hardware intel core_i5-12500 - No
Hardware intel core_i5-12500h - No
Hardware intel core_i5-12500t - No
Hardware intel core_i5-1250p - No
Hardware intel core_i5-12600 - No
Hardware intel core_i5-12600h - No
Hardware intel core_i5-12600hx - No
Hardware intel core_i5-12600k - No
Hardware intel core_i5-12600kf - No
Hardware intel core_i5-12600t - No
Hardware intel core_i7-1250u - No
Hardware intel core_i7-1255u - No
Hardware intel core_i7-1260p - No
Hardware intel core_i7-1260u - No
Hardware intel core_i7-12650h - No
Hardware intel core_i7-12650hx - No
Hardware intel core_i7-1265u - No
Hardware intel core_i7-12700 - No
Hardware intel core_i7-12700f - No
Hardware intel core_i7-12700h - No
Hardware intel core_i7-12700k - No
Hardware intel core_i7-12700kf - No
Hardware intel core_i7-12700t - No
Hardware intel core_i7-1270p - No
Hardware intel core_i7-12800h - No
Hardware intel core_i7-12800hx - No
Hardware intel core_i7-1280p - No
Hardware intel core_i7-12850hx - No
Hardware intel core_i9-12900 - No
Hardware intel core_i9-12900f - No
Hardware intel core_i9-12900h - No
Hardware intel core_i9-12900hk - No
Hardware intel core_i9-12900hx - No
Hardware intel core_i9-12900k - No
Hardware intel core_i9-12900kf - No
Hardware intel core_i9-12900ks - No
Hardware intel core_i9-12900t - No
Hardware intel core_i9-12950hx - No
Hardware intel pentium_8500 - No
Hardware intel pentium_8505 - No
Hardware intel pentium_gold_g7400 - No
Hardware intel pentium_gold_g7400t - No
Application insyde insydeh2o 05.53.28.0013 Yes
Hardware amd ryzen_3_7335u - No
Hardware amd ryzen_3_7440u - No
Hardware amd ryzen_5_6600h - No
Hardware amd ryzen_5_6600hs - No
Hardware amd ryzen_5_6600u - No
Hardware amd ryzen_5_7535hs - No
Hardware amd ryzen_5_7535u - No
Hardware amd ryzen_5_7540u - No
Hardware amd ryzen_5_7545u - No
Hardware amd ryzen_5_7640h - No
Hardware amd ryzen_5_7640u - No
Hardware amd ryzen_5_pro_7640hs - No
Hardware amd ryzen_7_6800h - No
Hardware amd ryzen_7_6800hs - No
Hardware amd ryzen_7_6800u - No
Hardware amd ryzen_7_7735hs - No
Hardware amd ryzen_7_7735u - No
Hardware amd ryzen_7_7736u - No
Hardware amd ryzen_7_7840h - No
Hardware amd ryzen_7_7840u - No
Hardware amd ryzen_7_pro_7840hs - No
Hardware amd ryzen_9_6900hs - No
Hardware amd ryzen_9_6900hx - No
Hardware amd ryzen_9_6980hs - No
Hardware amd ryzen_9_6980hx - No
Hardware amd ryzen_9_7940h - No
Hardware amd ryzen_9_7940hs - No
Hardware amd ryzen_9_pro_7940hs - No
Hardware amd ryzen_z1 - No
Hardware amd ryzen_z1_extreme - No
Hardware amd v314 - No
Hardware amd v3c16 - No
Hardware amd v3c18 - No
Hardware amd v3c44 - No
Hardware amd v3c48 - No
Application insyde insydeh2o 05.45.38.0005 Yes
Hardware intel celeron_7305l - No
Hardware intel core_i3-1215ul - No
Hardware intel core_i3-12300hl - No
Hardware intel core_i5-1235ul - No
Hardware intel core_i5-1245ul - No
Hardware intel core_i5-12500hl - No
Hardware intel core_i5-12600hl - No
Hardware intel core_i7-1255ul - No
Hardware intel core_i7-1265ul - No
Hardware intel core_i7-12700hl - No
Hardware intel core_i7-12800hl - No
Application insyde insydeh2o 05.53.23.0011 Yes
Hardware amd ryzen_7_7645hx - No
Hardware amd ryzen_7_7745hx - No
Hardware amd ryzen_7_7840hx - No
Hardware amd ryzen_9_7645hx3d - No
Hardware amd ryzen_9_7845hx - No
Hardware amd ryzen_9_7940hx - No
Hardware amd ryzen_9_7945hx - No
Application insyde insydeh2o 05.53.23.0014 Yes
Hardware amd athlon_gold_7220u - No
Hardware amd athlon_silver_7120u - No
Hardware amd ryzen_3_7320u - No
Hardware amd ryzen_5_7520u - No
Application insyde insydeh2o 05.53.22.0008 Yes
Hardware amd ryzen_5_7500f - No
Hardware amd ryzen_5_7600 - No
Hardware amd ryzen_5_7600x - No
Hardware amd ryzen_5_pro_7645 - No
Hardware amd ryzen_7_7700 - No
Hardware amd ryzen_7_7700x - No
Hardware amd ryzen_7_7800x3d - No
Hardware amd ryzen_7_pro_7745 - No
Hardware amd ryzen_9_7900 - No
Hardware amd ryzen_9_7900x - No
Hardware amd ryzen_9_7900x3d - No
Hardware amd ryzen_9_7950x - No
Hardware amd ryzen_9_7950x3d - No
Hardware amd ryzen_9_pro_7945 - No
Application insyde insydeh2o 05.44.30.0022 Yes
Hardware amd ryzen_3_7335u - No
Hardware amd ryzen_5_6600h - No
Hardware amd ryzen_5_6600hs - No
Hardware amd ryzen_5_6600u - No
Hardware amd ryzen_5_7535hs - No
Hardware amd ryzen_5_7535u - No
Hardware amd ryzen_7_6800h - No
Hardware amd ryzen_7_6800hs - No
Hardware amd ryzen_7_6800u - No
Hardware amd ryzen_7_7735hs - No
Hardware amd ryzen_7_7735u - No
Hardware amd ryzen_7_7736u - No
Hardware amd ryzen_9_6900hs - No
Hardware amd ryzen_9_6900hx - No
Hardware amd ryzen_9_6980hs - No
Hardware amd ryzen_9_6980hx - No
Application insyde insydeh2o 05.43.06.0021 Yes
Hardware amd van_gogh_0405 - No
Application insyde insydeh2o 05.42.37.0031 Yes
Hardware amd ryzen_3_5100 - No
Hardware amd ryzen_3_5125c - No
Hardware amd ryzen_3_5300g - No
Hardware amd ryzen_3_5300ge - No
Hardware amd ryzen_3_5400u - No
Hardware amd ryzen_3_5425u - No
Hardware amd ryzen_3_pro_7330u - No
Hardware amd ryzen_5_5500 - No
Hardware amd ryzen_5_5500h - No
Hardware amd ryzen_5_5500u - No
Hardware amd ryzen_5_5560u - No
Hardware amd ryzen_5_5600g - No
Hardware amd ryzen_5_5600ge - No
Hardware amd ryzen_5_5600h - No
Hardware amd ryzen_5_5600hs - No
Hardware amd ryzen_5_5600u - No
Hardware amd ryzen_5_5625u - No
Hardware amd ryzen_5_pro_7530u - No
Hardware amd ryzen_7_5700 - No
Hardware amd ryzen_7_5700g - No
Hardware amd ryzen_7_5700ge - No
Hardware amd ryzen_7_5700u - No
Hardware amd ryzen_7_5800h - No
Hardware amd ryzen_7_5800hs - No
Hardware amd ryzen_7_5800u - No
Hardware amd ryzen_7_5825u - No
Hardware amd ryzen_7_pro_7730u - No
Hardware amd ryzen_9_5900hs - No
Hardware amd ryzen_9_5900hx - No
Hardware amd ryzen_9_5980hs - No
Hardware amd ryzen3_5300u - No

References

How SecUtils Interprets This CVE

SecUtils normalizes and enriches National Vulnerability Database (NVD) records by standardizing vendor and product identifiers, aggregating vulnerability metadata from both NVD and MITRE sources, and providing structured context for security teams. For insyde's affected products, we extract Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) classifications, CVSS severity metrics, and reference data to enable rapid vulnerability prioritization and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and security operations.