CVE Vulnerabilities

CVE-2023-39284

Published: Nov 02, 2023 | Modified: Nov 15, 2023
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered in IhisiServicesSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. There are arbitrary calls to SetVariable with unsanitized arguments in the SMI handler.

Affected Software

Name Vendor Start Version End Version
Insydeh2o Insyde 5.2 (including) 5.2.05.28.33 (excluding)
Insydeh2o Insyde 5.3 (including) 5.3.05.37.33 (excluding)
Insydeh2o Insyde 5.4 (including) 5.4.05.45.33 (excluding)
Insydeh2o Insyde 5.5 (including) 5.5.05.53.33 (excluding)
Insydeh2o Insyde 5.6 (including) 5.6.05.60.33 (excluding)

References