First published: Wed Sep 28 2022(Updated: )
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. There is an SMM memory corruption vulnerability in the Software SMI handler in the PnpSmm driver.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Insyde InsydeH2O | >=5.4<05.44.30 | |
Insyde InsydeH2O | >=5.5<05.52.30 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-36448.
The severity of CVE-2022-36448 is high with a CVSS score of 8.2.
The affected software is Insyde InsydeH2O with kernel 5.0 through 5.5.
The CWE ID associated with this vulnerability is CWE-20.
To fix CVE-2022-36448, update to a version of Insyde InsydeH2O that is not vulnerable.