Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7x7c-2rvc-69fh

Опубликовано: 11 апр. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

An issue was discovered in ChipsetSvcSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. There is insufficient input validation in BIOS Guard updates. An attacker can induce memory corruption in SMM by supplying malformed inputs to the BIOS Guard SMI handler.

An issue was discovered in ChipsetSvcSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. There is insufficient input validation in BIOS Guard updates. An attacker can induce memory corruption in SMM by supplying malformed inputs to the BIOS Guard SMI handler.

EPSS

Процентиль: 40%
0.00179
Низкий

8.8 High

CVSS3

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 8.8
nvd
почти 3 года назад

An issue was discovered in ChipsetSvcSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. There is insufficient input validation in BIOS Guard updates. An attacker can induce memory corruption in SMM by supplying malformed inputs to the BIOS Guard SMI handler.

CVSS3: 7.9
fstec
почти 3 года назад

Уязвимость компонента ChipsetSvcSmm фреймворка для создания UEFI-прошивок InsydeH2O, позволяющая нарушителю вызвать повреждение памяти

EPSS

Процентиль: 40%
0.00179
Низкий

8.8 High

CVSS3

Дефекты

CWE-787