系微安全保證

最新安全公告

Security Advisory Archives

BIOS & BMC

Link
Summary
CVSS Score
INSYDE-SA-2023042Code change to accommodate OpenSSL 1.1.1u.
Low
Link
Summary
CVSS Score
INSYDE-SA-2023052SystemFirmwareManagementRuntimeDxe: potential arbitrary code execution in the DXE phase
5.3
Link
Summary
CVSS Score
INSYDE-SA-2023050Secure Boot Security Feature Bypass Vulnerability.
6.7
Link
Summary
CVSS Score
INSYDE-SA-2023036MeSetup UEFI variable may be overwritten and causes DOS attacks.
4.1
Link
Summary
CVSS Score
INSYDE-SA-2023038FDM TOCTOU access after measurement allows redirected code execution.
5.9
Link
Summary
CVSS Score
INSYDE-SA-2023047SysPasswordDxe: Cleartext storage of system password could lead to possible information disclosure.
5.1
Link
Summary
CVSS Score
INSYDE-SA-2023048Upgrade FreeType Build Tool to version 2.13.0 which addressed following vulnerability. This vulnerability was withdrawn by its CNA.
7.5
Link
Summary
CVSS Score
INSYDE-SA-2023051Upgrade curl to version 8.1.0
3.7~7.5
Link
Summary
CVSS Score
INSYDE-SA-2023039FvbServicesRuntimeDxe: Exposes an SMI handler that allows an attacker to interact with the SPI flash.
6.1
Link
Summary
CVSS Score
INSYDE-SA-2023044Secure Boot dbx update.
N/A
Link
Summary
CVSS Score
INSYDE-SA-2023018The CapsuleIFWUSmm driver does not check the return value which may cause memory leak.
5.3
Link
Summary
CVSS Score
INSYDE-SA-2023026[EDK2] Empty TPM Platform Auth.
7.5