CVE-2023-27471
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
18/08/2023
Last modified:
24/08/2023
Description
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. UEFI implementations do not correctly protect and validate information contained in the 'MeSetup' UEFI variable. On some systems, this variable can be overwritten using operating system APIs. Exploitation of this vulnerability could potentially lead to denial of service for the platform.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:insyde:insydeh2o:5.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:insyde:insydeh2o:5.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:insyde:insydeh2o:5.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:insyde:insydeh2o:5.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:insyde:insydeh2o:5.4:*:*:*:*:*:*:* | ||
| cpe:2.3:a:insyde:insydeh2o:5.5:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



