First published: Tue Apr 11 2023(Updated: )
An issue was discovered in ChipsetSvcSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. There is insufficient input validation in BIOS Guard updates. An attacker can induce memory corruption in SMM by supplying malformed inputs to the BIOS Guard SMI handler.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Insyde InsydeH2O | =05.42.52.0026 | |
Insyde InsydeH2O | =05.43.01.0026 | |
Insyde InsydeH2O | =05.43.12.0056 | |
Insyde InsydeH2O | =05.44.34.0054 | |
Insyde InsydeH2O | =05.44.45.0015 | |
Insyde InsydeH2O | =05.44.45.0028 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The CVE ID of this vulnerability is CVE-2023-22614.
The severity of CVE-2023-22614 is high with a CVSS score of 8.8.
The affected software is Insyde InsydeH2O versions 05.42.52.0026, 05.43.01.0026, 05.43.12.0056, 05.44.34.0054, 05.44.45.0015, and 05.44.45.0028.
The CWE of CVE-2023-22614 is CWE-20 and CWE-787.
To mitigate this vulnerability, apply the latest BIOS Guard updates provided by Insyde.