Cyber Resilience

CVE-2023-30633

Insydeh2O 5.3 – 5.3.05.37.17

Published
19 October 2023
Modified
21 November 2024
Patch / advisory
CVSS Score v3.1 5.3
Click a component to see what it means
Raw vectorCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
EPSS Score 0.0021 11th percentile
Risk Priority 39 floored blend · peak EPSS

CVSS and EPSS are reproduced from their sources (NVD, FIRST EPSS). Risk Priority is our own derived reading, not an NVD score.

Summary

CVE-2023-30633 is a medium-severity an unspecified weakness vulnerability in Insyde Insydeh2O. Its CVSS base score is 5.3 (Medium).

Operationally, ranked at the 11th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

An issue was discovered in TrEEConfigDriver in Insyde InsydeH2O with kernel 5.0 through 5.5. It can report false TPM PCR values, and thus mask malware activity. Devices use Platform Configuration Registers (PCRs) to record information about device and software configuration…

more

to ensure that the boot process is secure. (For example, Windows uses these PCR measurements to determine device health.) A vulnerable device can masquerade as a healthy device by extending arbitrary values into Platform Configuration Register (PCR) banks. This requires physical access to a target victim's device, or compromise of user credentials for a device. This issue is similar to CVE-2021-42299 (on Surface Pro devices).

CWE(s)

Related Threats

CVEs Like This One

CVE-2023-22614Same product: Insyde Insydeh2O
CVE-2023-27471Same product: Insyde Insydeh2O
CVE-2023-34195Same product: Insyde Insydeh2O
CVE-2024-52878Same product: Insyde Insydeh2O
CVE-2024-25079Same product: Insyde Insydeh2O
CVE-2023-31041Same product: Insyde Insydeh2O
CVE-2024-55567Same product: Insyde Insydeh2O
CVE-2023-27373Same product: Insyde Insydeh2O
CVE-2024-52877Same product: Insyde Insydeh2O
CVE-2023-39284Same product: Insyde Insydeh2O

Affected Assets

insyde
insydeh2o
5.2 · 5.3 — 5.3.05.37.17 · 5.4 — 5.4.05.45.17 · 5.5 — 5.5.05.53.17

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References