An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. UEFI implementations do not correctly protect and validate information contained in the 'MeSetup' UEFI variable. On some systems, this variable can be overwritten using operating system APIs. Exploitation of this vulnerability could potentially lead to denial of service for the platform.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.insyde.com/security-pledge/SA-2023036 |
History
Mon, 07 Oct 2024 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2023-08-18T00:00:00
Updated: 2024-10-07T19:45:21.227Z
Reserved: 2023-03-01T00:00:00
Link: CVE-2023-27471
Vulnrichment
Updated: 2024-08-02T12:09:43.512Z
NVD
Status : Modified
Published: 2023-08-18T19:15:12.243
Modified: 2024-11-21T07:52:58.327
Link: CVE-2023-27471
Redhat
No data.