系微安全保證

最新安全公告

Security Advisory Archives

BIOS & BMC

Link
Summary
CVSS Score
INSYDE-SA-2023022IhisiServicesSmm: Save State Register Not Checked Before Use.
6.4
Link
Summary
CVSS Score
INSYDE-SA-2023023IhisiServicesSmm: Write To Attacker Controlled Address.
7.3
Link
Summary
CVSS Score
INSYDE-SA-2023024[EDK2] MdeModulePkg/PiSmmCore: SmmEntryPoint underflow.
8.2
Link
Summary
CVSS Score
INSYDE-SA-2023025[EDK2] NetworkPkg/IScsiDxe: remotely exploitable buffer overflows.
8.1
Link
Summary
CVSS Score
INSYDE-SA-2023017H2OSmmDebugPrintErrorLevelLib: Variable size is not initialized before calling GetVariable.
6.4
Link
Summary
CVSS Score
INSYDE-SA-2023009DMA attacks on the FvbServicesRuntimeDxe shared buffer used by SMM and non-SMM code could cause TOCTOU issues which could lead to corruption of SMRAM and escalation of privileges.
8.2
Link
Summary
CVSS Score
INSYDE-SA-2023008DMA attacks on the AhciBusDxe shared buffer used by SMM and non-SMM code could cause TOCTOU issues which could lead to corruption of SMRAM and escalation of privileges.
7.5
Link
Summary
CVSS Score
INSYDE-SA-2023007DMA attacks on the VariableRuntimeDxe shared buffer used by SMM and non-SMM code could cause TOCTOU issues which could lead to corruption of SMRAM and escalation of privileges.
8.2
Link
Summary
CVSS Score
INSYDE-SA-2023006DMA attacks on the StorageSecurityCommandDxe shared buffer used by SMM and non-SMM code could cause TOCTOU issues which could lead to corruption of SMRAM and escalation of privileges.
8.2
Link
Summary
CVSS Score
INSYDE-SA-2023005DMA attacks on the HddPassword shared buffer used by SMM and non-SMM code could cause TOCTOU issues which could lead to corruption of SMRAM and escalation of privileges.
8.2
Link
Summary
CVSS Score
INSYDE-SA-2023003DMA attacks on the IHISI command buffer could cause TOCTOU issues which could lead to corruption of SMRAM and escalation of privileges.
8.2
Link
Summary
CVSS Score
INSYDE-SA-2023002DMA attacks on the FwBlockServiceSmm shared buffer used by SMM and non-SMM code could cause TOCTOU issues which could lead to corruption of SMRAM and escalation of privileges
8.2