// For flags

CVE-2023-27471

 

Severity Score

5.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Track
*SSVC
Descriptions

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. UEFI implementations do not correctly protect and validate information contained in the 'MeSetup' UEFI variable. On some systems, this variable can be overwritten using operating system APIs. Exploitation of this vulnerability could potentially lead to denial of service for the platform.

Se descubrió un problema en Insyde InsydeH2O con kernel 5.0 a 5.5. Las implementaciones UEFI no protegen ni validan correctamente la información contenida en la variable UEFI "MeSetup". En algunos sistemas, esta variable puede sobrescribirse utilizando las API del sistema operativo. La explotación de esta vulnerabilidad podría conducir potencialmente a la denegación de servicio de la plataforma.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
* Common Vulnerability Scoring System
SSVC
  • Decision:Track
Exploitation
None
Automatable
No
Tech. Impact
Partial
* Organization's Worst-case Scenario
Timeline
  • 2023-03-01 CVE Reserved
  • 2023-08-18 CVE Published
  • 2023-08-19 EPSS Updated
  • 2024-10-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Insyde
Search vendor "Insyde"
Insydeh2o
Search vendor "Insyde" for product "Insydeh2o"
5.0
Search vendor "Insyde" for product "Insydeh2o" and version "5.0"
-
Affected
Insyde
Search vendor "Insyde"
Insydeh2o
Search vendor "Insyde" for product "Insydeh2o"
5.1
Search vendor "Insyde" for product "Insydeh2o" and version "5.1"
-
Affected
Insyde
Search vendor "Insyde"
Insydeh2o
Search vendor "Insyde" for product "Insydeh2o"
5.2
Search vendor "Insyde" for product "Insydeh2o" and version "5.2"
-
Affected
Insyde
Search vendor "Insyde"
Insydeh2o
Search vendor "Insyde" for product "Insydeh2o"
5.3
Search vendor "Insyde" for product "Insydeh2o" and version "5.3"
-
Affected
Insyde
Search vendor "Insyde"
Insydeh2o
Search vendor "Insyde" for product "Insydeh2o"
5.4
Search vendor "Insyde" for product "Insydeh2o" and version "5.4"
-
Affected
Insyde
Search vendor "Insyde"
Insydeh2o
Search vendor "Insyde" for product "Insydeh2o"
5.5
Search vendor "Insyde" for product "Insydeh2o" and version "5.5"
-
Affected