Improper access control in the Insyde software tools may allow an authenticated user to potentially enable escalation of privilege, or information disclosure via local access. This is a software vulnerability, not a firmware issue. Affected tools include: H2OFFT version 3.02~5.28, 100.00.00.00~100.00.08.23 and 200.00.00.01~200.00.00.05, H2OOAE before version 200.00.00.02, H2OSDE before version 200.00.00.07, H2OUVE before version 200.00.02.02, H2OPCM before version 100.00.06.00, H2OELV before version 100.00.02.08.
Name | Vendor | Start Version | End Version |
---|---|---|---|
H2oelv | Insyde | * | 100.00.02.08 (excluding) |
H2offt | Insyde | 3.02 (including) | 5.28 (including) |
H2offt | Insyde | 100.00.00.00 (including) | 100.00.08.23 (including) |
H2offt | Insyde | 200.00.00.01 (including) | 200.00.00.05 (including) |
H2ooae | Insyde | * | 200.00.00.02 (excluding) |
H2opcm | Insyde | * | 100.00.06.00 (excluding) |
H2osde | Insyde | * | 200.00.00.07 (excluding) |
H2ouve | Insyde | * | 200.00.02.02 (excluding) |