← Back

CVE-2023-27471

nvd nist
Published: Aug 18, 2023Modified: Nov 21, 2024

JSON object

Loading...
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Exploitability: 1.8 / Impact: 3.6
Source: NVD

Description

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. UEFI implementations do not correctly protect and validate information contained in the 'MeSetup' UEFI variable. On some systems, this variable can be overwritten using operating system APIs. Exploitation of this vulnerability could potentially lead to denial of service for the platform.

Affected (6)

Products: Insyde: Insydeh2o
1 product
Insydeh2o
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Insyde
Version 5.0
Version 5.1
Version 5.2
Version 5.3
Version 5.4
Version 5.5

References (2)

Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.