Insyde's Security Pledge

Recent Security Advisories

Security Advisory Archives

BIOS & BMC

Link
Summary
CVSS Score
INSYDE-SA-2024001SMM memory corruption vulnerability could lead to escalating privileges in SMM. (CWE-822)
7.4
Link
Summary
CVSS Score
INSYDE-SA-2023067PnpSmm: Possible out of bounds in SMM communication buffer, leading to tampering.
4.7
Link
Summary
CVSS Score
INSYDE-SA-2023040IhisiServiceSmm: A vulnerability in the module that could allow an attacker to modify UEFI variables.
6.1
Link
Summary
CVSS Score
INSYDE-SA-2020001AhciBusDxe: Improper input validation might lead to arbitrary code execution vulnerability at SMM level.
7.2
Link
Summary
CVSS Score
INSYDE-SA-2023068Upgrade curl to version 8.5.0.
5.3~6.5
Link
Summary
CVSS Score
INSYDE-SA-2023066VU#132380 Vulnerabilities in EDK2 NetworkPkg IP stack implementation.
5.3~8.3
Link
Summary
CVSS Score
INSYDE-SA-2023031VU#275256 Vulnerabilities in EDK2 Reference implementation of the UEFI Specification.
7
Link
Summary
CVSS Score
INSYDE-SA-2023065curl: SOCKS5 heap buffer overflow
9.8
Link
Summary
CVSS Score
INSYDE-SA-2023064HTTP headers eat all memory.
7.5
Link
Summary
CVSS Score
INSYDE-SA-2023062Code change to accommodate OpenSSL 1.1.1w.
N/A
Link
Summary
CVSS Score
INSYDE-SA-2023053Improper input validation may be exploited via local access.
5.5~6.1
Link
Summary
CVSS Score
INSYDE-SA-2023060Upgrade OpenSSL to 1.1.1v
Low