Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-55567


Improper input validation was discovered in UsbCoreDxe in Insyde InsydeH2O kernel 5.4 before 05.47.01, 5.5 before 05.55.01, 5.6 before 05.62.01, and 5.7 before 05.71.01. The SMM module has an SMM call out vulnerability which can be used to write arbitrary memory inside SMRAM and execute arbitrary code at SMM level.


Published

2025-06-12T17:15:28.707

Last Modified

2025-08-20T17:31:31.460

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application insyde insydeh2o < 5.4.05.47.01 Yes
Application insyde insydeh2o < 5.5.05.55.01 Yes
Application insyde insydeh2o < 5.6.05.62.01 Yes
Application insyde insydeh2o < 5.7.05.71.01 Yes

References