Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-22616

Опубликовано: 12 апр. 2023
Источник: nvd
CVSS3: 7.8
EPSS Низкий

Описание

An issue was discovered in Insyde InsydeH2O with kernel 5.2 through 5.5. The Save State register is not checked before use. The IhisiSmm driver does not check the value of a save state register before use. Due to insufficient input validation, an attacker can corrupt SMRAM.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:insyde:insydeh2o:*:*:*:*:*:*:*:*
Версия от 5.2 (включая) до 5.5 (включая)

EPSS

Процентиль: 22%
0.00071
Низкий

7.8 High

CVSS3

Дефекты

CWE-610
CWE-610

Связанные уязвимости

CVSS3: 7.8
github
почти 3 года назад

An issue was discovered in Insyde InsydeH2O with kernel 5.2 through 5.5. The Save State register is not checked before use. The IhisiSmm driver does not check the value of a save state register before use. Due to insufficient input validation, an attacker can corrupt SMRAM.

EPSS

Процентиль: 22%
0.00071
Низкий

7.8 High

CVSS3

Дефекты

CWE-610
CWE-610