Skip to main content

Vendor archive

insyde CVEs

Beta · best-effort

103 CVEs tagged to vendor insyde3 Critical, 75 High, 24 Medium, 1 Low, 0 Unrated.

CVE-2023-22615

Published Apr 11, 2023

An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. IHISI subfunction execution may corrupt SMRAM. An attacker can pass an address in the RCX save…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2023-22614

Published Apr 11, 2023

An issue was discovered in ChipsetSvcSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. There is insufficient input validation in BIOS Guard updates. An attacker can induce memo…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-22612

Published Apr 11, 2023

An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. A malicious host OS can invoke an Insyde SMI handler with malformed arguments, resulting in me…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-32477

Published Feb 15, 2023

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the FvbServicesRuntimeDxe shared buffer used by SMM and non-SMM code could cause TOCTOU rac…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-32475

Published Feb 15, 2023

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the VariableRuntimeDxe shared buffer used by SMM and non-SMM code could cause TOCTOU race-c…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-32469

Published Feb 15, 2023

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the PnpSmm shared buffer used by SMM and non-SMM code could cause TOCTOU race-condition iss…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-32953

Published Feb 15, 2023

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the SdHostDriver buffer used by SMM and non-SMM code could cause TOCTOU race-condition issu…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-32476

Published Feb 15, 2023

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the AhciBusDxe shared buffer used by SMM and non-SMM code could cause TOCTOU race-condition…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-32473

Published Feb 15, 2023

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the HddPassword shared buffer used by SMM and non-SMM code could cause TOCTOU race-conditio…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-32470

Published Feb 15, 2023

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the FwBlockServiceSmm shared buffer used by SMM and non-SMM code could cause TOCTOU race-co…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-32955

Published Feb 15, 2023

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the NvmExpressDxe buffer used by SMM and non-SMM code could cause TOCTOU race-condition iss…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-32954

Published Feb 15, 2023

An issue was discovered in Insyde InsydeH2O with kernel 5.1 through 5.5. DMA attacks on the SdMmcDevice buffer used by SMM and non-SMM code could cause TOCTOU race-condition issue…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-32478

Published Feb 15, 2023

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the IdeBusDxe shared buffer used by SMM and non-SMM code could cause TOCTOU race-condition…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-32474

Published Feb 15, 2023

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the StorageSecurityCommandDxe shared buffer used by SMM and non-SMM code could cause TOCTOU…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-32471

Published Feb 15, 2023

An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. The IhisiDxe driver uses the command buffer to pass input and output data. By modifying the co…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-36337

Published Nov 23, 2022

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. A stack buffer overflow vulnerability in the MebxConfiguration driver leads to arbitrary code execution. C…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-35407

Published Nov 22, 2022

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. A stack buffer overflow leads to arbitrary code execution in the SetupUtility driver on Intel platforms. A…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-35897

Published Nov 21, 2022

An stack buffer overflow vulnerability leads to arbitrary code execution issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. If the attacker modifies specific UE…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-29279

Published Nov 15, 2022

Use of a untrusted pointer allows tampering with SMRAM and OS memory in SdHostDriver and SdMmcDevice Use of a untrusted pointer allows tampering with SMRAM and OS memory in SdHost…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-29278

Published Nov 15, 2022

Incorrect pointer checks within the NvmExpressDxe driver can allow tampering with SMRAM and OS memory Incorrect pointer checks within the NvmExpressDxe driver can allow tampering…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-29276

Published Nov 15, 2022

SMI functions in AhciBusDxe use untrusted inputs leading to corruption of SMRAM. SMI functions in AhciBusDxe use untrusted inputs leading to corruption of SMRAM. This issue was di…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-30772

Published Nov 15, 2022

Manipulation of the input address in PnpSmm function 0x52 could be used by malware to overwrite SMRAM or OS kernel memory. Function 0x52 of the PnpSmm driver is passed the address…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-30771

Published Nov 15, 2022

Initialization function in PnpSmm could lead to SMRAM corruption when using subsequent PNP SMI functions Initialization function in PnpSmm could lead to SMRAM corruption when usin…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-30283

Published Nov 15, 2022

In UsbCoreDxe, tampering with the contents of the USB working buffer using DMA while certain USB transactions are in process leads to a TOCTOU problem that could be used by an att…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-29275

Published Nov 15, 2022

In UsbCoreDxe, untrusted input may allow SMRAM or OS memory tampering Use of untrusted pointers could allow OS or SMRAM memory tampering leading to escalation of privileges. This…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort
Showing 26-50 of 103 CVEsPage 2 of 5