48 lines
1.7 KiB
JSON
Raw Normal View History

{
"id": "CVE-2023-28149",
"sourceIdentifier": "cve@mitre.org",
"published": "2024-07-31T19:15:10.993",
"lastModified": "2024-11-07T17:35:03.810",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "An issue was discovered in the IhisiServiceSmm module in Insyde InsydeH2O with kernel 5.2 before 05.28.42, 5.3 before 05.37.42, 5.4 before 05.45.39, 5.5 before 05.53.39, and 5.6 before 05.60.39 that could allow an attacker to modify UEFI variables."
},
{
"lang": "es",
"value": " Se descubri\u00f3 un problema en el m\u00f3dulo IhisiServiceSmm en Insyde InsydeH2O con kernel 5.2 anterior a 05.28.42, 5.3 anterior a 05.37.42, 5.4 anterior a 05.45.39, 5.5 anterior a 05.53.39 y 5.6 anterior a 05.60.39 que podr\u00eda permitir a un atacante modificar Variables UEFI."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:L",
"attackVector": "LOCAL",
"attackComplexity": "HIGH",
"privilegesRequired": "HIGH",
"userInteraction": "NONE",
"scope": "CHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "HIGH",
"availabilityImpact": "LOW",
"baseScore": 6.1,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 0.8,
"impactScore": 4.7
}
]
},
"references": [
{
"url": "https://www.insyde.com/security-pledge/SA-2023040",
"source": "cve@mitre.org"
}
]
}