VYPR

UEFI

by Insyde

CVEs (3)

  • CVE-2026-6484HigAug 12, 2026
    risk 0.53cvss 8.2epss

    In an UEFI, Lack of verified boot to certain FV may cause arbitrary code execution.

  • CVE-2025-4275HigJun 11, 2025
    risk 0.51cvss 7.8epss 0.00

    A vulnerability in the digital signature verification process does not properly validate variable attributes which allows an attacker to bypass signature verification by creating a non-authenticated NVRAM variable. An attacker may to execute arbitrary signed UEFI code and bypass…

  • CVE-2024-39707MedNov 14, 2024
    risk 0.34cvss 5.3epss 0.00

    Insyde IHISI function 0x49 can restore factory defaults for certain UEFI variables without further authentication by default, which could lead to a possible roll-back attack in certain platforms. This is fixed in: kernel 5.2, version 05.29.19; kernel 5.3, version 05.38.19;…