VYPR
Medium severity5.5NVD Advisory· Published Aug 18, 2023· Updated Jun 17, 2026

CVE-2023-27471

CVE-2023-27471

Description

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. UEFI implementations do not correctly protect and validate information contained in the 'MeSetup' UEFI variable. On some systems, this variable can be overwritten using operating system APIs. Exploitation of this vulnerability could potentially lead to denial of service for the platform.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

8
  • Insyde/InsydeH2O7 versions
    cpe:2.3:a:insyde:insydeh2o:5.0:*:*:*:*:*:*:*+ 6 more
    • cpe:2.3:a:insyde:insydeh2o:5.0:*:*:*:*:*:*:*
    • cpe:2.3:a:insyde:insydeh2o:5.1:*:*:*:*:*:*:*
    • cpe:2.3:a:insyde:insydeh2o:5.2:*:*:*:*:*:*:*
    • cpe:2.3:a:insyde:insydeh2o:5.3:*:*:*:*:*:*:*
    • cpe:2.3:a:insyde:insydeh2o:5.4:*:*:*:*:*:*:*
    • cpe:2.3:a:insyde:insydeh2o:5.5:*:*:*:*:*:*:*
    • (no CPE)range: 5.0 - 5.5
  • Insyde/InsydeH2Odescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.