Insyde's Security Pledge

Recent Security Advisories

Security Advisory Archives

BIOS & BMC

Link
Summary
CVSS Score
INSYDE-SA-2023059H2O-0802-2301 Code change to accommodate OpenSSL 1.1.1v
N/A
Link
Summary
CVSS Score
INSYDE-SA-2023054AsfSecureBootDxe: Stack buffer overflow vulnerability leading to arbitrary code execution during DXE phase.
4.1
Link
Summary
CVSS Score
INSYDE-SA-2023055CsmInt10HookSmm: SMM memory corruption vulnerability in SMM driver (SMRAM write).
5.3
Link
Summary
CVSS Score
INSYDE-SA-2023056IhisiServicesSmm: Arbitrary calls to SetVariable with unsanitized arguments in SMI handler.
6.1
Link
Summary
CVSS Score
INSYDE-SA-2023045TrEEConfigDriver: Vulnerable devices can report false TPM PCR values masking malware activity.
6.1
Link
Summary
CVSS Score
INSYDE-SA-2023043Upgrade OpenSSL to 1.1.1u.
Low-Medium
Link
Summary
CVSS Score
INSYDE-SA-2023058curl: fopen race condition.
5.5
Link
Summary
CVSS Score
INSYDE-SA-2023061dbus: Unprivileged users to crash dbus-daemon
6.5
Link
Summary
CVSS Score
INSYDE-SA-2023042Code change to accommodate OpenSSL 1.1.1u.
Low
Link
Summary
CVSS Score
INSYDE-SA-2023052SystemFirmwareManagementRuntimeDxe: potential arbitrary code execution in the DXE phase
5.3
Link
Summary
CVSS Score
INSYDE-SA-2023050Secure Boot Security Feature Bypass Vulnerability.
6.7
Link
Summary
CVSS Score
INSYDE-SA-2023036MeSetup UEFI variable may be overwritten and causes DOS attacks.
4.1