CVE-2023-22614: Input Validation
Published Apr 11, 2023
·Updated
An issue was discovered in ChipsetSvcSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. There is insufficient input validation in BIOS Guard updates. An attacker can induce memory corruption in SMM by supplying malformed inputs to the BIOS Guard SMI handler.
Affected Software
6 affected components
Insyde InsydeH2O=05.42.52.0026
Insyde InsydeH2O=05.43.01.0026
Insyde InsydeH2O=05.43.12.0056
Insyde InsydeH2O=05.44.34.0054
Insyde InsydeH2O=05.44.45.0015
Insyde InsydeH2O=05.44.45.0028
Event History
Apr 11, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2023-22614.
2
What is the severity of CVE-2023-22614?
The severity of CVE-2023-22614 is high with a CVSS score of 8.8.
3
What is the affected software?
The affected software is Insyde InsydeH2O versions 05.42.52.0026, 05.43.01.0026, 05.43.12.0056, 05.44.34.0054, 05.44.45.0015, and 05.44.45.0028.
4
What is the CWE of CVE-2023-22614?
The CWE of CVE-2023-22614 is CWE-20 and CWE-787.
5
How can I mitigate this vulnerability?
To mitigate this vulnerability, apply the latest BIOS Guard updates provided by Insyde.