Insyde's Security Pledge

Recent Security Advisories

Security Advisory Archives

BIOS & BMC

Link
Summary
CVSS Score
INSYDE-SA-2023035Insufficient TSEG Overlap Checks.
6.4
Link
Summary
CVSS Score
INSYDE-SA-2023028OOB Read If “Console Redirection” EFI Variable Is Tampered.
3.0
Link
Summary
CVSS Score
INSYDE-SA-2023027IhisiSmm: Possible out of bounds in IHISI command buffer, leading to tampering.
5.3
Link
Summary
CVSS Score
INSYDE-SA-2023019IhisiServicesSmm: Memory Corruption in FTBS SMI Handler.
8.1
Link
Summary
CVSS Score
INSYDE-SA-2023020ChipsetSvcSmm: insufficient Input Validation In BIOS Guard Updates.
7.9
Link
Summary
CVSS Score
INSYDE-SA-2023021IhisiServicesSmm: IHISI Subfunction Execution May Corrupt SMRAM.
6.4
Link
Summary
CVSS Score
INSYDE-SA-2023022IhisiServicesSmm: Save State Register Not Checked Before Use.
6.4
Link
Summary
CVSS Score
INSYDE-SA-2023023IhisiServicesSmm: Write To Attacker Controlled Address.
7.3
Link
Summary
CVSS Score
INSYDE-SA-2023024[EDK2] MdeModulePkg/PiSmmCore: SmmEntryPoint underflow.
8.2
Link
Summary
CVSS Score
INSYDE-SA-2023025[EDK2] NetworkPkg/IScsiDxe: remotely exploitable buffer overflows.
8.1
Link
Summary
CVSS Score
INSYDE-SA-2023017H2OSmmDebugPrintErrorLevelLib: Variable size is not initialized before calling GetVariable.
6.4
Link
Summary
CVSS Score
INSYDE-SA-2023009DMA attacks on the FvbServicesRuntimeDxe shared buffer used by SMM and non-SMM code could cause TOCTOU issues which could lead to corruption of SMRAM and escalation of privileges.
8.2