Vulnerability Details CVE-2023-27373
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. Due to insufficient input validation, an attacker can tamper with a runtime-accessible EFI variable to cause a dynamic BAR setting to overlap SMRAM.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 11.1%
CVSS Severity
CVSS v3 Score 5.5
Products affected by CVE-2023-27373
-
cpe:2.3:a:insyde:insydeh2o:5.0
-
cpe:2.3:a:insyde:insydeh2o:5.1
-
cpe:2.3:a:insyde:insydeh2o:5.2
-
cpe:2.3:a:insyde:insydeh2o:5.3
-
cpe:2.3:a:insyde:insydeh2o:5.4
-
cpe:2.3:a:insyde:insydeh2o:5.5