Vulnerabilities > Insyde > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-11-15 CVE-2022-31243 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Insyde Kernel
Update description and links DMA transactions which are targeted at input buffers used for the software SMI handler used by the FvbServicesRuntimeDxe driver could cause SMRAM corruption through a TOCTOU attack..
local
high complexity
insyde CWE-367
6.4
2022-11-15 CVE-2022-32267 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Insyde Kernel
DMA transactions which are targeted at input buffers used for the SmmResourceCheckDxe software SMI handler cause SMRAM corruption (a TOCTOU attack) DMA transactions which are targeted at input buffers used for the software SMI handler used by the SmmResourceCheckDxe driver could cause SMRAM corruption through a TOCTOU attack...
local
high complexity
insyde CWE-367
6.4
2022-11-15 CVE-2022-33906 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Insyde Kernel
DMA transactions which are targeted at input buffers used for the FwBlockServiceSmm software SMI handler could cause SMRAM corruption through a TOCTOU attack.
local
high complexity
insyde CWE-367
6.4
2022-11-15 CVE-2022-33986 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Insyde Kernel
DMA attacks on the parameter buffer used by the VariableRuntimeDxe software SMI handler could lead to a TOCTOU attack.
local
high complexity
insyde CWE-367
6.4
2022-11-14 CVE-2022-33907 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Insyde Kernel
DMA transactions which are targeted at input buffers used for the software SMI handler used by the IdeBusDxe driver could cause SMRAM corruption through a TOCTOU attack...
local
high complexity
insyde CWE-367
6.4
2022-11-14 CVE-2022-33982 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Insyde Kernel
DMA attacks on the parameter buffer used by the Int15ServiceSmm software SMI handler could lead to a TOCTOU attack on the SMI handler and lead to corruption of SMRAM.
local
high complexity
insyde CWE-367
6.4
2022-11-14 CVE-2022-30773 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Insyde Kernel
DMA attacks on the parameter buffer used by the IhisiSmm driver could change the contents after parameter values have been checked but before they are used (a TOCTOU attack).
local
high complexity
insyde CWE-367
6.4
2022-11-14 CVE-2022-32266 Out-of-bounds Write vulnerability in Insyde Kernel
DMA attacks on the parameter buffer used by a software SMI handler used by the driver PcdSmmDxe could lead to a TOCTOU attack on the SMI handler and lead to corruption of other ACPI fields and adjacent memory fields.
local
high complexity
insyde CWE-787
6.4
2022-09-22 CVE-2022-35896 Improper Input Validation vulnerability in Insyde Insydeh2O
An issue SMM memory leak vulnerability in SMM driver (SMRAM was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5.
local
low complexity
insyde CWE-20
6.0
2022-02-03 CVE-2021-33625 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
An issue was discovered in Kernel 5.x in Insyde InsydeH2O, affecting HddPassword.
6.9