Skip to main content

Vendor archive

insyde CVEs

Beta · best-effort

103 CVEs tagged to vendor insyde3 Critical, 75 High, 24 Medium, 1 Low, 0 Unrated.

CVE-2024-55567

Published Jun 12, 2025

Improper input validation was discovered in UsbCoreDxe in Insyde InsydeH2O kernel 5.4 before 05.47.01, 5.5 before 05.55.01, 5.6 before 05.62.01, and 5.7 before 05.71.01. The SMM m…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-52880

Published May 15, 2025

An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kernel 5.4 before version 05.46.50, kernel 5.5 before version 0…

CVSS 7.9 · High
Vendor/product tagsBeta · best-effort

CVE-2024-52879

Published May 15, 2025

An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kernel 5.4 before version 05.46.50, kernel 5.5 before version 0…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-52878

Published May 15, 2025

An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kernel 5.4 before version 05.46.50, kernel 5.5 before version 0…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-52877

Published May 15, 2025

An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kernel 5.4 before version 05.46.50, kernel 5.5 before version 0…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-49200

Published Apr 15, 2025

An issue was discovered in AcpiS3SaveDxe and ChipsetSvcDxe in Insyde InsydeH2O with kernel 5.2 though 5.7. A potential DXE memory corruption vulnerability has been identified. The…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-25079

Published May 15, 2024

A memory corruption vulnerability in HddPassword in Insyde InsydeH2O kernel 5.2 before 05.29.09, kernel 5.3 before 05.38.09, kernel 5.4 before 05.46.09, kernel 5.5 before 05.54.09…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2024-25078

Published May 15, 2024

A memory corruption vulnerability in StorageSecurityCommandDxe in Insyde InsydeH2O before kernel 5.2: IB19130163 in 05.29.07, kernel 5.3: IB19130163 in 05.38.07, kernel 5.4: IB191…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2023-47252

Published Apr 26, 2024

An issue was discovered in PnpSmm in Insyde InsydeH2O with kernel 5.0 through 5.6. There is a possible out-of-bounds access in the SMM communication buffer, leading to tampering.…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-46897

Published Apr 22, 2024

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. The CapsuleIFWUSmm driver does not check the return value from a method or function. This can prevent it f…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24351

Published Dec 16, 2023

TOCTOU race-condition vulnerability in Insyde InsydeH2O with Kernel 5.2 before version 05.27.29, Kernel 5.3 before version 05.36.29, Kernel 5.4 version before 05.44.13, and Kernel…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-39283

Published Nov 2, 2023

An SMM memory corruption vulnerability in the SMM driver (SMRAM write) in CsmInt10HookSmm in Insyde InsydeH2O with kernel 5.0 through 5.5 allows attackers to send arbitrary data t…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-39284

Published Nov 2, 2023

An issue was discovered in IhisiServicesSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. There are arbitrary calls to SetVariable with unsanitized arguments in the SMI handler.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-30633

Published Oct 19, 2023

An issue was discovered in TrEEConfigDriver in Insyde InsydeH2O with kernel 5.0 through 5.5. It can report false TPM PCR values, and thus mask malware activity. Devices use Platfo…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-34195

Published Sep 18, 2023

An issue was discovered in SystemFirmwareManagementRuntimeDxe in Insyde InsydeH2O with kernel 5.0 through 5.5. The implementation of the GetImage method retrieves the value of a r…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-33834

Published Sep 8, 2023

An issue was discovered in iscflashx64.sys 3.9.3.0 in Insyde H2OFFT 6.20.00. When handling IOCTL 0x22229a, the input used to allocate a buffer and copy memory is mishandled. This…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27471

Published Aug 18, 2023

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. UEFI implementations do not correctly protect and validate information contained in the 'MeSetup' UEFI var…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-31041

Published Aug 14, 2023

An issue was discovered in SysPasswordDxe in Insyde InsydeH2O with kernel 5.0 through 5.5. System password information could optionally be stored in cleartext, which might lead to…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27373

Published Aug 7, 2023

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. Due to insufficient input validation, an attacker can tamper with a runtime-accessible EFI variable to cau…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-28468

Published Aug 3, 2023

An issue was discovered in FvbServicesRuntimeDxe in Insyde InsydeH2O with kernel 5.0 through 5.5. The FvbServicesRuntimeDxe SMM module exposes an SMI handler that allows an attack…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-25600

Published Aug 3, 2023

An issue was discovered in InsydeH2O. A malicious operating system can tamper with a runtime-writable EFI variable, leading to out-of-bounds memory reads and a denial of service.…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-22616

Published Apr 12, 2023

An issue was discovered in Insyde InsydeH2O with kernel 5.2 through 5.5. The Save State register is not checked before use. The IhisiSmm driver does not check the value of a save…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-24350

Published Apr 12, 2023

An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. IHISI function 0x17 verifies that the output buffer lies within the command buffer but does no…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-22613

Published Apr 11, 2023

An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. It is possible to write to an attacker-controlled address. An attacker could invoke an SMI han…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 103 CVEsPage 1 of 5