Medium severity5.5NVD Advisory· Published Aug 7, 2023· Updated Jun 17, 2026
CVE-2023-27373
CVE-2023-27373
Description
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. Due to insufficient input validation, an attacker can tamper with a runtime-accessible EFI variable to cause a dynamic BAR setting to overlap SMRAM.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8cpe:2.3:a:insyde:insydeh2o:5.0:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:insyde:insydeh2o:5.0:*:*:*:*:*:*:*
- cpe:2.3:a:insyde:insydeh2o:5.1:*:*:*:*:*:*:*
- cpe:2.3:a:insyde:insydeh2o:5.2:*:*:*:*:*:*:*
- cpe:2.3:a:insyde:insydeh2o:5.3:*:*:*:*:*:*:*
- cpe:2.3:a:insyde:insydeh2o:5.4:*:*:*:*:*:*:*
- cpe:2.3:a:insyde:insydeh2o:5.5:*:*:*:*:*:*:*
- (no CPE)range: 5.0 - 5.5
- Insyde/InsydeH2Odescription
Patches
Vulnerability mechanics
References
1- www.insyde.com/security-pledge/SA-2023035nvdVendor Advisory
News mentions
0No linked articles in our index yet.