CVE-2023-39284: Medium severity insyde h2o vulnerability
Published Nov 2, 2023
·Updated
An issue was discovered in IhisiServicesSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. There are arbitrary calls to SetVariable with unsanitized arguments in the SMI handler.
Affected Software
5 affected components
Insyde InsydeH2O>=5.2<5.2.05.28.33
Insyde InsydeH2O>=5.3<5.3.05.37.33
Insyde InsydeH2O>=5.4<5.4.05.45.33
Insyde InsydeH2O>=5.5<5.5.05.53.33
Insyde InsydeH2O>=5.6<5.6.05.60.33
Event History
Nov 2, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-39284?
The severity of CVE-2023-39284 is medium.
2
What software is affected by CVE-2023-39284?
Insyde InsydeH2O versions 5.0 through 5.5 are affected by CVE-2023-39284.
3
How can I fix CVE-2023-39284?
To fix CVE-2023-39284, it is recommended to apply the latest security patches and updates for Insyde InsydeH2O.
4
Where can I find more information about CVE-2023-39284?
You can find more information about CVE-2023-39284 on the Insyde security pledge page and in security advisory SA-2023056.