Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
insyde kernel 5.1 vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2022-30772
Manipulation of the input address in PnpSmm function 0x52 could be used by malware to overwrite SMRAM or OS kernel memory. Function 0x52 of the PnpSmm driver is passed the address and size of data to write into the SMBIOS table, but manipulation of the address could be used by ma...
Insyde Kernel
NA
CVE-2022-30283
In UsbCoreDxe, tampering with the contents of the USB working buffer using DMA while certain USB transactions are in process leads to a TOCTOU problem that could be used by an malicious user to cause SMRAM corruption and escalation of privileges The UsbCoreDxe module creates a wo...
Insyde Kernel
7.2
CVSSv2
CVE-2021-42060
An issue exists in Insyde InsydeH2O Kernel 5.0 up to and including 05.08.41, Kernel 5.1 up to and including 05.16.41, Kernel 5.2 prior to 05.23.22, and Kernel 5.3 prior to 05.32.22. An Int15ServiceSmm SMM callout vulnerability allows an malicious user to hijack execution flow of ...
Insyde Insydeh2o
5
CVSSv2
CVE-2020-5956
An issue exists in SdLegacySmm in Insyde InsydeH2O with kernel 5.1 prior to 05.15.11, 5.2 prior to 05.25.11, 5.3 prior to 05.34.11, and 5.4 prior to 05.42.11. The software SMI handler allows untrusted external input because it does not verify CommBuffer.
Insyde Insydeh2o
4.6
CVSSv2
CVE-2021-42113
An issue exists in StorageSecurityCommandDxe in Insyde InsydeH2O with Kernel 5.1 prior to 05.14.28, Kernel 5.2 prior to 05.24.28, and Kernel 5.3 prior to 05.32.25. An SMM callout vulnerability allows an malicious user to hijack execution flow of code running in System Management ...
Insyde Insydeh2o
7.5
CVSSv2
CVE-2021-41842
An issue exists in AtaLegacySmm in the kernel 5.0 prior to 05.08.46, 5.1 prior to 05.16.46, 5.2 prior to 05.26.46, 5.3 prior to 05.35.46, 5.4 prior to 05.43.46, and 5.5 prior to 05.51.45 in Insyde InsydeH2O. Code execution can occur because the SMI handler lacks a CommBuffer chec...
Insyde Insydeh2o
6.9
CVSSv2
CVE-2022-24030
An issue exists in AhciBusDxe in Insyde InsydeH2O with kernel 5.1 up to and including 5.5. An SMM memory corruption vulnerability allows an malicious user to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM.
Insyde Insydeh2o
7.2
CVSSv2
CVE-2022-24031
An issue exists in NvmExpressDxe in Insyde InsydeH2O with kernel 5.1 up to and including 5.5. An SMM memory corruption vulnerability allows an malicious user to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM.
Insyde Insydeh2o
7.2
CVSSv2
CVE-2021-45971
An issue exists in SdHostDriver in Insyde InsydeH2O with kernel 5.1 prior to 05.16.25, 5.2 prior to 05.26.25, 5.3 prior to 05.35.25, 5.4 prior to 05.43.25, and 5.5 prior to 05.51.25. A vulnerability exists in the SMM (System Management Mode) branch that registers a SWSMI handler ...
Insyde Insydeh2o
6.9
CVSSv2
CVE-2021-43522
An issue exists in Insyde InsydeH2O with kernel 5.1 through 2021-11-08, 5.2 through 2021-11-08, and 5.3 through 2021-11-08. A StorageSecurityCommandDxe SMM memory corruption vulnerability allows an malicious user to write fixed or predictable data to SMRAM. Exploiting this issue ...
Insyde Insydeh2o
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-29895
blind SQL injection
CVE-2024-5064
CVE-2023-52677
CVE-2023-52682
CVE-2024-30051
CVE-2024-35849
remote attackers
remote
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
NEXT »