An issue was discovered in FvbServicesRuntimeDxe in Insyde InsydeH2O with kernel 5.0 through 5.5. The FvbServicesRuntimeDxe SMM module exposes an SMI handler that allows an attacker to interact with the SPI flash at run-time from the OS.
Metrics
Affected Vendors & Products
References
History
Thu, 17 Oct 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published: 2023-08-03T00:00:00
Updated: 2024-10-17T20:05:38.922Z
Reserved: 2023-03-15T00:00:00
Link: CVE-2023-28468
Updated: 2024-08-02T12:38:25.284Z
Status : Modified
Published: 2023-08-03T15:15:20.167
Modified: 2024-11-21T07:55:09.023
Link: CVE-2023-28468
No data.