Vulnerabilities > Insyde > Insydeh2O > High

DATE CVE VULNERABILITY TITLE RISK
2023-11-02 CVE-2023-39283 Out-of-bounds Write vulnerability in Insyde Insydeh2O
An SMM memory corruption vulnerability in the SMM driver (SMRAM write) in CsmInt10HookSmm in Insyde InsydeH2O with kernel 5.0 through 5.5 allows attackers to send arbitrary data to SMM which could lead to privilege escalation.
local
low complexity
insyde CWE-787
7.8
2023-09-18 CVE-2023-34195 Unspecified vulnerability in Insyde Insydeh2O
An issue was discovered in SystemFirmwareManagementRuntimeDxe in Insyde InsydeH2O with kernel 5.0 through 5.5.
local
low complexity
insyde
7.8
2023-08-14 CVE-2023-31041 Cleartext Storage of Sensitive Information vulnerability in Insyde Insydeh2O
An issue was discovered in SysPasswordDxe in Insyde InsydeH2O with kernel 5.0 through 5.5.
network
low complexity
insyde CWE-312
7.5
2023-04-12 CVE-2023-22616 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Insyde Insydeh2O
An issue was discovered in Insyde InsydeH2O with kernel 5.2 through 5.5.
local
low complexity
insyde CWE-610
7.8
2023-04-11 CVE-2023-22613 Out-of-bounds Write vulnerability in Insyde Insydeh2O
An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5.
local
low complexity
insyde CWE-787
8.8
2023-04-11 CVE-2023-22614 Out-of-bounds Write vulnerability in Insyde Insydeh2O
An issue was discovered in ChipsetSvcSmm in Insyde InsydeH2O with kernel 5.0 through 5.5.
local
low complexity
insyde CWE-787
8.8
2023-04-11 CVE-2023-22612 Out-of-bounds Write vulnerability in Insyde Insydeh2O
An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5.
local
low complexity
insyde CWE-787
8.8
2023-04-11 CVE-2023-22615 Out-of-bounds Write vulnerability in Insyde Insydeh2O 05.37.03/05.45.01/05.53.01
An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5.
local
low complexity
insyde CWE-787
8.4
2023-02-15 CVE-2022-32469 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Insyde Insydeh2O
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5.
local
high complexity
insyde CWE-367
7.0
2023-02-15 CVE-2022-32475 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Insyde Insydeh2O
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5.
local
high complexity
insyde CWE-367
7.0