VYPR
Medium severity6.0NVD Advisory· Published Sep 22, 2022· Updated Jun 17, 2026

CVE-2022-35894

CVE-2022-35894

Description

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. The SMI handler for the FwBlockServiceSmm driver uses an untrusted pointer as the location to copy data to an attacker-specified buffer, leading to information disclosure.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Insyde/InsydeH2O2 versions
    cpe:2.3:a:insyde:insydeh2o:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:insyde:insydeh2o:*:*:*:*:*:*:*:*range: >=5.0,<05.09.37
    • (no CPE)range: 5.0 - 5.5
  • Insyde/InsydeH2Odescription

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.