Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-10280
HistoryFeb 08, 2022 - 12:00 a.m.

Insyde InsydeH2O Buffer Overflow Vulnerability (CNVD-2022-10280)

2022-02-0800:00:00
China National Vulnerability Database
www.cnvd.org.cn
13

0.001 Low

EPSS

Percentile

26.7%

Insyde InsydeH2O is a C source from Insyde Software (Taiwan, China) that implements the new technology “EFI/UEFI” specification, designed to replace the traditional BIOS (Basic Input/Output System). Operating System (H2O) UEFI firmware suffers from a buffer overflow vulnerability that could be exploited to access the UEFI DXE driver and execute arbitrary code.

0.001 Low

EPSS

Percentile

26.7%

Related for CNVD-2022-10280