CVE-2023-47252

April 26, 2024, 12:58 p.m.

Awaiting Analysis
CVE has been recently published to the CVE List and has been received by the NVD.

Products

Insyde InsydeH2O

  • 5.0 - 5.6

Source

cve@mitre.org

Tags

CVE-2023-47252 details

Published : April 26, 2024, 3:15 a.m.
Last Modified : April 26, 2024, 12:58 p.m.

Description

An issue was discovered in PnpSmm in Insyde InsydeH2O with kernel 5.0 through 5.6. There is a possible out-of-bounds access in the SMM communication buffer, leading to tampering. The PNP-related SMI sub-functions do not verify data size before getting it from the communication buffer, which could lead to possible circumstances where the data immediately following the command buffer could be destroyed with a fixed value. This is fixed in kernel 5.2 v05.28.45, kernel 5.3 v05.37.45, kernel 5.4 v05.45.45, kernel 5.5 v05.53.45, and kernel 5.6 v05.60.45.

CVSS Score

1 2 3 4 5 6 7 8 9 10

Weakness

Weakness Name Description

References

URL Source
https://www.insyde.com/security-pledge/SA-2023067 cve@mitre.org
This website uses the NVD API, but is not approved or certified by it.