Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f9jq-jhvv-4xmw

Опубликовано: 12 апр. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

An issue was discovered in Insyde InsydeH2O with kernel 5.2 through 5.5. The Save State register is not checked before use. The IhisiSmm driver does not check the value of a save state register before use. Due to insufficient input validation, an attacker can corrupt SMRAM.

An issue was discovered in Insyde InsydeH2O with kernel 5.2 through 5.5. The Save State register is not checked before use. The IhisiSmm driver does not check the value of a save state register before use. Due to insufficient input validation, an attacker can corrupt SMRAM.

EPSS

Процентиль: 22%
0.00071
Низкий

7.8 High

CVSS3

Дефекты

CWE-610

Связанные уязвимости

CVSS3: 7.8
nvd
почти 3 года назад

An issue was discovered in Insyde InsydeH2O with kernel 5.2 through 5.5. The Save State register is not checked before use. The IhisiSmm driver does not check the value of a save state register before use. Due to insufficient input validation, an attacker can corrupt SMRAM.

EPSS

Процентиль: 22%
0.00071
Низкий

7.8 High

CVSS3

Дефекты

CWE-610