CVE-2022-35894

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. The SMI handler for the FwBlockServiceSmm driver uses an untrusted pointer as the location to copy data to an attacker-specified buffer, leading to information disclosure.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
insydeinsydeh2o
5.0 ≤
𝑥
< 05.09.37
insydeinsydeh2o
5.1 ≤
𝑥
< 5.17.37
insydeinsydeh2o
5.2 ≤
𝑥
< 05.27.29
insydeinsydeh2o
5.3 ≤
𝑥
< 05.36.29
insydeinsydeh2o
5.4 ≤
𝑥
< 05.44.29
insydeinsydeh2o
5.5 ≤
𝑥
< 05.52.29
𝑥
= Vulnerable software versions