Cyber Resilience

CVE-2023-27471

Insydeh2O 5.0 … 5.5

Published
18 August 2023
Modified
21 November 2024
Patch / advisory
CVSS Score v3.1 5.5
Click a component to see what it means
Raw vectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Score 0.0017 7th percentile
Risk Priority 41 floored blend · peak EPSS

CVSS and EPSS are reproduced from their sources (NVD, FIRST EPSS). Risk Priority is our own derived reading, not an NVD score.

Summary

CVE-2023-27471 is a medium-severity an unspecified weakness vulnerability in Insyde Insydeh2O. Its CVSS base score is 5.5 (Medium).

Operationally, ranked at the 7th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. UEFI implementations do not correctly protect and validate information contained in the 'MeSetup' UEFI variable. On some systems, this variable can be overwritten using operating system APIs. Exploitation…

more

of this vulnerability could potentially lead to denial of service for the platform.

CWE(s)

Related Threats

CVEs Like This One

CVE-2023-22614Same product: Insyde Insydeh2O
CVE-2023-34195Same product: Insyde Insydeh2O
CVE-2024-52878Same product: Insyde Insydeh2O
CVE-2024-25079Same product: Insyde Insydeh2O
CVE-2023-31041Same product: Insyde Insydeh2O
CVE-2024-55567Same product: Insyde Insydeh2O
CVE-2023-27373Same product: Insyde Insydeh2O
CVE-2023-30633Same product: Insyde Insydeh2O
CVE-2024-52877Same product: Insyde Insydeh2O
CVE-2023-39284Same product: Insyde Insydeh2O

Affected Assets

insyde
insydeh2o
5.0, 5.1, 5.2, 5.3, 5.4

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References