PT-2022-22131 · Insyde · Insydeh2O Uefi Firmware

Published

2022-11-14

·

Updated

2025-04-30

·

CVE-2022-34325

CVSS v3.1

7.8

High

VectorAV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions InsydeH2O UEFI firmware (affected versions not specified)
Description The issue concerns DMA transactions targeted at input buffers used for the StorageSecurityCommandDxe software SMI handler, which could cause SMRAM corruption through a TOCTOU attack. This was discovered by Insyde engineering based on a general description provided.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Time Of Check To Time Of Use

Weakness Enumeration

Related Identifiers

CVE-2022-34325

Affected Products

Insydeh2O Uefi Firmware