Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-24532 | Tcg2Smm has a vulnerability which can be used to write arbitrary memory inside SMRAM and execute arbitrary code at SMM level. |
Solution
Kernel 5.2, Version 05.2A.21 Kernel 5.3, Version 05.39.21 Kernel 5.4, Version 05.47.21 Kernel 5.5, Version 05.55.21 Kernel 5.6, Version 05.62.21 Kernel 5.7, Version 05.71.21
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.insyde.com/security-pledge/sa-2025005/ |
|
Thu, 14 Aug 2025 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Insyde
Insyde insydeh2o |
|
| Vendors & Products |
Insyde
Insyde insydeh2o |
Wed, 13 Aug 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 13 Aug 2025 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Tcg2Smm has a vulnerability which can be used to write arbitrary memory inside SMRAM and execute arbitrary code at SMM level. | |
| Title | Tcg2Smm: improper input validation may lead to arbitrary code execution | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Insyde
Published:
Updated: 2025-08-14T05:54:24.230Z
Reserved: 2025-05-05T02:10:48.657Z
Link: CVE-2025-4277
Updated: 2025-08-13T13:21:50.279Z
Status : Awaiting Analysis
Published: 2025-08-13T02:15:26.690
Modified: 2025-08-13T17:33:46.673
Link: CVE-2025-4277
No data.
OpenCVE Enrichment
Updated: 2025-08-13T21:47:03Z
EUVD