An issue was discovered in FvbServicesRuntimeDxe in Insyde InsydeH2O with kernel 5.0 through 5.5. The FvbServicesRuntimeDxe SMM module exposes an SMI handler that allows an attacker to interact with the SPI flash at run-time from the OS.
Metrics
Affected Vendors & Products
References
History
Thu, 17 Oct 2024 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-10-17T20:05:38.922Z
Reserved: 2023-03-15T00:00:00
Link: CVE-2023-28468

Updated: 2024-08-02T12:38:25.284Z

Status : Modified
Published: 2023-08-03T15:15:20.167
Modified: 2024-11-21T07:55:09.023
Link: CVE-2023-28468

No data.