Cyber Resilience

CVE-2023-39284

Insydeh2O 5.2 – 5.2.05.28.33

Published
02 November 2023
Modified
21 November 2024
Patch / advisory
CVSS Score v3.1 5.5
Click a component to see what it means
Raw vectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS Score 0.0018 7th percentile
Risk Priority 41 floored blend · peak EPSS

CVSS and EPSS are reproduced from their sources (NVD, FIRST EPSS). Risk Priority is our own derived reading, not an NVD score.

Summary

CVE-2023-39284 is a medium-severity an unspecified weakness vulnerability in Insyde Insydeh2O. Its CVSS base score is 5.5 (Medium).

Operationally, ranked at the 7th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

An issue was discovered in IhisiServicesSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. There are arbitrary calls to SetVariable with unsanitized arguments in the SMI handler.

CWE(s)

Related Threats

CVEs Like This One

CVE-2023-22614Same product: Insyde Insydeh2O
CVE-2023-27471Same product: Insyde Insydeh2O
CVE-2023-34195Same product: Insyde Insydeh2O
CVE-2024-52878Same product: Insyde Insydeh2O
CVE-2024-25079Same product: Insyde Insydeh2O
CVE-2023-31041Same product: Insyde Insydeh2O
CVE-2024-55567Same product: Insyde Insydeh2O
CVE-2023-27373Same product: Insyde Insydeh2O
CVE-2023-30633Same product: Insyde Insydeh2O
CVE-2024-52877Same product: Insyde Insydeh2O

Affected Assets

insyde
insydeh2o
5.2 — 5.2.05.28.33 · 5.3 — 5.3.05.37.33 · 5.4 — 5.4.05.45.33

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References