CVE-2022-35894: Medium severity insyde h2o vulnerability
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. The SMI handler for the FwBlockServiceSmm driver uses an untrusted pointer as the location to copy data to an attacker-specified buffer, leading to information disclosure.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-35894?
CVE-2022-35894 is a vulnerability in Insyde InsydeH2O that allows an attacker to disclose information through the SMI handler for the FwBlockServiceSmm driver.
How severe is CVE-2022-35894?
CVE-2022-35894 has a severity level of 6, which is considered medium.
What software is affected by CVE-2022-35894?
Insyde InsydeH2O versions 5.0 through 5.5 are affected by CVE-2022-35894.
How can an attacker exploit CVE-2022-35894?
An attacker can exploit CVE-2022-35894 by using an untrusted pointer to copy data to an attacker-controlled buffer, leading to information disclosure.
Are there any references related to CVE-2022-35894?
Yes, you can find more information about CVE-2022-35894 at the following references: [Reference 1](https://binarly.io/advisories/BRLY-2022-018/index.html), [Reference 2](https://www.insyde.com/security-pledge), [Reference 3](https://www.insyde.com/security-pledge/SA-2022030)