Medium severity6.5NVD Advisory· Published Aug 3, 2023· Updated Jun 17, 2026
CVE-2023-28468
CVE-2023-28468
Description
An issue was discovered in FvbServicesRuntimeDxe in Insyde InsydeH2O with kernel 5.0 through 5.5. The FvbServicesRuntimeDxe SMM module exposes an SMI handler that allows an attacker to interact with the SPI flash at run-time from the OS.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Insyde/InsydeH2Odescription
Patches
Vulnerability mechanics
References
2- www.insyde.com/security-pledge/SA-2023039nvdVendor Advisory
- www.insyde.com/security-pledgenvdNot Applicable
News mentions
0No linked articles in our index yet.