系微安全保證

最新安全公告

Security Advisory Archives

BIOS & BMC

Link
Summary
CVSS Score
INSYDE-SA-2023031VU#275256 Vulnerabilities in EDK2 Reference implementation of the UEFI Specification.
7
Link
Summary
CVSS Score
INSYDE-SA-2023065curl: SOCKS5 heap buffer overflow
9.8
Link
Summary
CVSS Score
INSYDE-SA-2023064HTTP headers eat all memory.
7.5
Link
Summary
CVSS Score
INSYDE-SA-2023062Code change to accommodate OpenSSL 1.1.1w.
N/A
Link
Summary
CVSS Score
INSYDE-SA-2023053Improper input validation may be exploited via local access.
5.5~6.1
Link
Summary
CVSS Score
INSYDE-SA-2023060Upgrade OpenSSL to 1.1.1v
Low
Link
Summary
CVSS Score
INSYDE-SA-2023059H2O-0802-2301 Code change to accommodate OpenSSL 1.1.1v
N/A
Link
Summary
CVSS Score
INSYDE-SA-2023054AsfSecureBootDxe: Stack buffer overflow vulnerability leading to arbitrary code execution during DXE phase.
4.1
Link
Summary
CVSS Score
INSYDE-SA-2023055CsmInt10HookSmm: SMM memory corruption vulnerability in SMM driver (SMRAM write).
5.3
Link
Summary
CVSS Score
INSYDE-SA-2023056IhisiServicesSmm: Arbitrary calls to SetVariable with unsanitized arguments in SMI handler.
6.1
Link
Summary
CVSS Score
INSYDE-SA-2023045TrEEConfigDriver: Vulnerable devices can report false TPM PCR values masking malware activity.
6.1
Link
Summary
CVSS Score
INSYDE-SA-2023043Upgrade OpenSSL to 1.1.1u.
Low-Medium