Vulnerability Name: | CVE-2022-35896 (CCN-236932) | ||||||||||||
Assigned: | 2022-09-21 | ||||||||||||
Published: | 2022-09-21 | ||||||||||||
Updated: | 2022-09-26 | ||||||||||||
Summary: | An issue SMM memory leak vulnerability in SMM driver (SMRAM was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. An attacker can dump SMRAM contents via the software SMI provided by the FvbServicesRuntimeDxe driver to read the contents of SMRAM, leading to information disclosure. | ||||||||||||
CVSS v3 Severity: | 6.0 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N) 5.2 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C)
5.2 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 4.6 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:C/I:N/A:N)
| ||||||||||||
Vulnerability Type: | CWE-119 | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2022-35896 Source: MISC Type: Exploit, Third Party Advisory https://binarly.io/advisories/BRLY-2022-025/index.html Source: XF Type: UNKNOWN insyde-cve202235896-info-disc(236932) Source: MISC Type: Vendor Advisory https://www.insyde.com/security-pledge Source: CCN Type: Insyde Security Advisory 2022034 SMM memory leak vulnerability in SMM driver (SMRAM read) in InsydeH2O Source: MISC Type: Vendor Advisory https://www.insyde.com/security-pledge/SA-2022034 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||
BACK |