Insyde's Security Pledge

Recent Security Advisories

Security Advisory Archives

BIOS & BMC

Link
Summary
CVSS Score
INSYDE-SA-2022013SMM callout vulnerability allowing a possible attacker to hijack execution flow of a code running in System Management Mode. Exploiting this issue could lead to escalating privileges to SMM.
8.2
Link
Summary
CVSS Score
INSYDE-SA-2022012SMM memory corruption vulnerability allowing a possible attacker to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM.
7.5
Link
Summary
CVSS Score
INSYDE-SA-2022011SMM memory corruption vulnerability allowing a possible attacker to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM.
7.5
Link
Summary
CVSS Score
INSYDE-SA-2022010SMM callout vulnerability allowing a possible attacker to hijack execution flow of a code running in System Management Mode. Exploiting this issue could lead to escalating privileges to SMM.
8.2
Link
Summary
CVSS Score
INSYDE-SA-2022009SMM memory corruption vulnerability allowing a possible attacker to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM.
7.5
Link
Summary
CVSS Score
INSYDE-SA-2022008SMM callout vulnerability allowing a possible attacker to hijack execution flow of a code running in System Management Mode. Exploiting this issue could lead to escalating privileges to SMM.
8.2
Link
Summary
CVSS Score
INSYDE-SA-2022007SMM callout vulnerability allowing a possible attacker to hijack execution flow of a code running in System Management Mode. Exploiting this issue could lead to escalating privileges to SMM.
7.5
Link
Summary
CVSS Score
INSYDE-SA-2022006Stack overflow vulnerability that allows a local root user to access UEFI DXE driver and execute arbitrary code.
8.2
Link
Summary
CVSS Score
INSYDE-SA-2022001A vulnerability exists in SMM (System Management Mode) branch that registers a SWSMI handler that does not sufficiently check or validate the allocated buffer pointer.
8.2
Link
Summary
CVSS Score
INSYDE-SA-2022005SdLegacySmm: Software SMI handler does not verify CommBuffer, allowing untrusted external input (CVE-2020-5956).
7.5
Link
Summary
CVSS Score
INSYDE-SA-2022004AtaLegacySmm: SMI handler does not check CommBuffer leading to possible arbitrary code execution.
8.2
Link
Summary
CVSS Score
INSYDE-SA-2022003A vulnerability exists in SMM (System Management Mode) branch that registers a SWSMI handler that does not sufficiently check or validate the allocated buffer pointer(CommBuffer + 8 location). This can be used by an attacker to corrupt data in SMRAM memory and even lead to arbitrary code execution.
8.2