Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-10288
HistoryFeb 08, 2022 - 12:00 a.m.

Insyde InsydeH2O has an unspecified vulnerability (CNVD-2022-10288)

2022-02-0800:00:00
China National Vulnerability Database
www.cnvd.org.cn
11

0.001 Low

EPSS

Percentile

20.6%

Insyde InsydeH2O is a C source from Insyde Software (Taiwan, China) that implements the new technology “EFI/UEFI” specification, designed to replace the legacy BIOS (Basic Input/Output System).A security vulnerability exists in Insyde InsydeH2O. The vulnerability stems from the System Management Interrupt (SWSMI) handler of the InsydeH2O UEFI firmware code located in the SWSMI handler that dereferences the gRT (EFI_RUNTIME_SERVICES) pointer to call the GetVariable service located outside of SMRAM. No detailed vulnerability details are currently available.

0.001 Low

EPSS

Percentile

20.6%

Related for CNVD-2022-10288