CVE-2023-28149: Medium severity insyde h2o vulnerability
An issue was discovered in the IhisiServiceSmm module in Insyde InsydeH2O with kernel 5.2 before 05.28.42, 5.3 before 05.37.42, 5.4 before 05.45.39, 5.5 before 05.53.39, and 5.6 before 05.60.39 that could allow an attacker to modify UEFI variables.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-28149?
CVE-2023-28149 has a medium severity level as it allows potential modification of UEFI variables.
How do I fix CVE-2023-28149?
To fix CVE-2023-28149, update the InsydeH2O BIOS to versions 05.28.42, 05.37.42, 05.45.39, 05.53.39, or 05.60.39 or later.
Which systems are affected by CVE-2023-28149?
The affected systems include InsydeH2O BIOS versions prior to 05.28.42, 05.37.42, 05.45.39, 05.53.39, and 05.60.39.
What type of vulnerability is CVE-2023-28149?
CVE-2023-28149 is a UEFI privilege escalation vulnerability that could allow attackers to modify system variables.
Is there a vendor patch available for CVE-2023-28149?
Yes, Insyde has released updates that address the vulnerabilities identified in CVE-2023-28149.