« Volver al listado

CVE-2023-27373

Estado: ModificadaMedia (5.5)—

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. Due to insufficient input validation, an attacker can tamper with a runtime-accessible EFI variable to cause a dynamic BAR setting to overlap SMRAM.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-27373",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-27373",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-03-06T15:54:54.808087Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      },
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2023-08-07T15:15:10.893",
  "references": [
    {
      "url": "https://www.insyde.com/security-pledge/SA-2023035",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.insyde.com/security-pledge/SA-2023035",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. Due to insufficient input validation, an attacker can tamper with a runtime-accessible EFI variable to cause a dynamic BAR setting to overlap SMRAM."
    },
    {
      "lang": "es",
      "value": "Se descubrió un problema en Insyde InsydeH2O con los kernels 5.0 a 5.5. Debido a una validación de entrada insuficiente, un atacante puede alterar una variable EFI accesible en tiempo de ejecución para provocar que una configuración de BAR dinámica se superponga a SMRAM."
    }
  ],
  "lastModified": "2026-06-17T05:44:54.013",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:insyde:insydeh2o:5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C50E9CE0-9960-4939-A6C1-E6E69F464456"
            },
            {
              "criteria": "cpe:2.3:a:insyde:insydeh2o:5.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6F486B49-3E4C-43BD-9165-8D159EBE74F9"
            },
            {
              "criteria": "cpe:2.3:a:insyde:insydeh2o:5.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2BA6B7DE-2275-41D9-BFD0-066AC3912055"
            },
            {
              "criteria": "cpe:2.3:a:insyde:insydeh2o:5.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "24E601E3-FCF5-4907-BCB1-E5D331896E40"
            },
            {
              "criteria": "cpe:2.3:a:insyde:insydeh2o:5.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "88E0151F-0A27-4F69-96B4-A40B00719107"
            },
            {
              "criteria": "cpe:2.3:a:insyde:insydeh2o:5.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E87C1381-CDD4-4A1C-AF59-32873BDF2730"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}