UEFI
by Insyde
CVEs (3)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-6484 | Hig | 0.53 | 8.2 | — | Aug 12, 2026 | In an UEFI, Lack of verified boot to certain FV may cause arbitrary code execution. | ||
| CVE-2025-4275 | Hig | 0.51 | 7.8 | 0.00 | Jun 11, 2025 | A vulnerability in the digital signature verification process does not properly validate variable attributes which allows an attacker to bypass signature verification by creating a non-authenticated NVRAM variable. An attacker may to execute arbitrary signed UEFI code and bypass… | ||
| CVE-2024-39707 | Med | 0.34 | 5.3 | 0.00 | Nov 14, 2024 | Insyde IHISI function 0x49 can restore factory defaults for certain UEFI variables without further authentication by default, which could lead to a possible roll-back attack in certain platforms. This is fixed in: kernel 5.2, version 05.29.19; kernel 5.3, version 05.38.19;… |
- risk 0.53cvss 8.2epss —
In an UEFI, Lack of verified boot to certain FV may cause arbitrary code execution.
- risk 0.51cvss 7.8epss 0.00
A vulnerability in the digital signature verification process does not properly validate variable attributes which allows an attacker to bypass signature verification by creating a non-authenticated NVRAM variable. An attacker may to execute arbitrary signed UEFI code and bypass…
- risk 0.34cvss 5.3epss 0.00
Insyde IHISI function 0x49 can restore factory defaults for certain UEFI variables without further authentication by default, which could lead to a possible roll-back attack in certain platforms. This is fixed in: kernel 5.2, version 05.29.19; kernel 5.3, version 05.38.19;…