VYPR
Medium severity5.5NVD Advisory· Published Aug 7, 2023· Updated Jun 17, 2026

CVE-2023-27373

CVE-2023-27373

Description

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. Due to insufficient input validation, an attacker can tamper with a runtime-accessible EFI variable to cause a dynamic BAR setting to overlap SMRAM.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

8
  • Insyde/InsydeH2O7 versions
    cpe:2.3:a:insyde:insydeh2o:5.0:*:*:*:*:*:*:*+ 6 more
    • cpe:2.3:a:insyde:insydeh2o:5.0:*:*:*:*:*:*:*
    • cpe:2.3:a:insyde:insydeh2o:5.1:*:*:*:*:*:*:*
    • cpe:2.3:a:insyde:insydeh2o:5.2:*:*:*:*:*:*:*
    • cpe:2.3:a:insyde:insydeh2o:5.3:*:*:*:*:*:*:*
    • cpe:2.3:a:insyde:insydeh2o:5.4:*:*:*:*:*:*:*
    • cpe:2.3:a:insyde:insydeh2o:5.5:*:*:*:*:*:*:*
    • (no CPE)range: 5.0 - 5.5
  • Insyde/InsydeH2Odescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.