VulnerabilityModified
CVE-2023-27471
Exploitation of this vulnerability could potentially lead to denial of service for the platform.
MEDIUM 5.5EPSS 0.17%
Does this matter?
Lower severity and a low EPSS score (0.17%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. UEFI implementations do not correctly protect and validate information contained in the 'MeSetup' UEFI variable. On some systems, this variable can be overwritten using operating system APIs. Exploitation of this vulnerability could potentially lead to denial of service for the platform.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.17% probability · 7th percentile
- CISA KEV
- Not listed
- Affected
- insyde/insydeh2o
- Source
- cve@mitre.org
References
- https://www.insyde.com/security-pledge/SA-2023036Vendor Advisory
- https://www.insyde.com/security-pledge/SA-2023036Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.