Skip to main content

Vendor/product archive

insyde / insydeh2o CVEs

Beta · best-effort

65 CVEs tagged to insyde / insydeh2o2 Critical, 53 High, 10 Medium, 0 Low, 0 Unrated.

CVE-2024-55567

Published Jun 12, 2025

Improper input validation was discovered in UsbCoreDxe in Insyde InsydeH2O kernel 5.4 before 05.47.01, 5.5 before 05.55.01, 5.6 before 05.62.01, and 5.7 before 05.71.01. The SMM m…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-52879

Published May 15, 2025

An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kernel 5.4 before version 05.46.50, kernel 5.5 before version 0…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-52878

Published May 15, 2025

An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kernel 5.4 before version 05.46.50, kernel 5.5 before version 0…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-52877

Published May 15, 2025

An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kernel 5.4 before version 05.46.50, kernel 5.5 before version 0…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-25079

Published May 15, 2024

A memory corruption vulnerability in HddPassword in Insyde InsydeH2O kernel 5.2 before 05.29.09, kernel 5.3 before 05.38.09, kernel 5.4 before 05.46.09, kernel 5.5 before 05.54.09…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2022-24351

Published Dec 16, 2023

TOCTOU race-condition vulnerability in Insyde InsydeH2O with Kernel 5.2 before version 05.27.29, Kernel 5.3 before version 05.36.29, Kernel 5.4 version before 05.44.13, and Kernel…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-39283

Published Nov 2, 2023

An SMM memory corruption vulnerability in the SMM driver (SMRAM write) in CsmInt10HookSmm in Insyde InsydeH2O with kernel 5.0 through 5.5 allows attackers to send arbitrary data t…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-39284

Published Nov 2, 2023

An issue was discovered in IhisiServicesSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. There are arbitrary calls to SetVariable with unsanitized arguments in the SMI handler.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-30633

Published Oct 19, 2023

An issue was discovered in TrEEConfigDriver in Insyde InsydeH2O with kernel 5.0 through 5.5. It can report false TPM PCR values, and thus mask malware activity. Devices use Platfo…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-34195

Published Sep 18, 2023

An issue was discovered in SystemFirmwareManagementRuntimeDxe in Insyde InsydeH2O with kernel 5.0 through 5.5. The implementation of the GetImage method retrieves the value of a r…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27471

Published Aug 18, 2023

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. UEFI implementations do not correctly protect and validate information contained in the 'MeSetup' UEFI var…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-31041

Published Aug 14, 2023

An issue was discovered in SysPasswordDxe in Insyde InsydeH2O with kernel 5.0 through 5.5. System password information could optionally be stored in cleartext, which might lead to…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27373

Published Aug 7, 2023

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. Due to insufficient input validation, an attacker can tamper with a runtime-accessible EFI variable to cau…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-22616

Published Apr 12, 2023

An issue was discovered in Insyde InsydeH2O with kernel 5.2 through 5.5. The Save State register is not checked before use. The IhisiSmm driver does not check the value of a save…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-24350

Published Apr 12, 2023

An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. IHISI function 0x17 verifies that the output buffer lies within the command buffer but does no…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-22613

Published Apr 11, 2023

An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. It is possible to write to an attacker-controlled address. An attacker could invoke an SMI han…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-22615

Published Apr 11, 2023

An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. IHISI subfunction execution may corrupt SMRAM. An attacker can pass an address in the RCX save…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2023-22614

Published Apr 11, 2023

An issue was discovered in ChipsetSvcSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. There is insufficient input validation in BIOS Guard updates. An attacker can induce memo…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-22612

Published Apr 11, 2023

An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. A malicious host OS can invoke an Insyde SMI handler with malformed arguments, resulting in me…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-32477

Published Feb 15, 2023

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the FvbServicesRuntimeDxe shared buffer used by SMM and non-SMM code could cause TOCTOU rac…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-32475

Published Feb 15, 2023

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the VariableRuntimeDxe shared buffer used by SMM and non-SMM code could cause TOCTOU race-c…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-32469

Published Feb 15, 2023

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the PnpSmm shared buffer used by SMM and non-SMM code could cause TOCTOU race-condition iss…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-32953

Published Feb 15, 2023

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the SdHostDriver buffer used by SMM and non-SMM code could cause TOCTOU race-condition issu…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-32476

Published Feb 15, 2023

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the AhciBusDxe shared buffer used by SMM and non-SMM code could cause TOCTOU race-condition…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 65 CVEsPage 1 of 3