Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-39284


An issue was discovered in IhisiServicesSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. There are arbitrary calls to SetVariable with unsanitized arguments in the SMI handler.


Published

2023-11-02T21:15:09.747

Last Modified

2024-11-21T08:15:03.857

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.5 (MEDIUM)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application insyde insydeh2o < 5.2.05.28.33 Yes
Application insyde insydeh2o < 5.3.05.37.33 Yes
Application insyde insydeh2o < 5.4.05.45.33 Yes
Application insyde insydeh2o < 5.5.05.53.33 Yes
Application insyde insydeh2o < 5.6.05.60.33 Yes

References