mirror of
https://github.com/fkie-cad/nvd-json-data-feeds.git
synced 2025-06-07 05:28:59 +00:00
48 lines
1.7 KiB
JSON
48 lines
1.7 KiB
JSON
{
|
|
"id": "CVE-2023-28149",
|
|
"sourceIdentifier": "cve@mitre.org",
|
|
"published": "2024-07-31T19:15:10.993",
|
|
"lastModified": "2024-11-07T17:35:03.810",
|
|
"vulnStatus": "Awaiting Analysis",
|
|
"cveTags": [],
|
|
"descriptions": [
|
|
{
|
|
"lang": "en",
|
|
"value": "An issue was discovered in the IhisiServiceSmm module in Insyde InsydeH2O with kernel 5.2 before 05.28.42, 5.3 before 05.37.42, 5.4 before 05.45.39, 5.5 before 05.53.39, and 5.6 before 05.60.39 that could allow an attacker to modify UEFI variables."
|
|
},
|
|
{
|
|
"lang": "es",
|
|
"value": " Se descubri\u00f3 un problema en el m\u00f3dulo IhisiServiceSmm en Insyde InsydeH2O con kernel 5.2 anterior a 05.28.42, 5.3 anterior a 05.37.42, 5.4 anterior a 05.45.39, 5.5 anterior a 05.53.39 y 5.6 anterior a 05.60.39 que podr\u00eda permitir a un atacante modificar Variables UEFI."
|
|
}
|
|
],
|
|
"metrics": {
|
|
"cvssMetricV31": [
|
|
{
|
|
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
|
|
"type": "Secondary",
|
|
"cvssData": {
|
|
"version": "3.1",
|
|
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:L",
|
|
"attackVector": "LOCAL",
|
|
"attackComplexity": "HIGH",
|
|
"privilegesRequired": "HIGH",
|
|
"userInteraction": "NONE",
|
|
"scope": "CHANGED",
|
|
"confidentialityImpact": "NONE",
|
|
"integrityImpact": "HIGH",
|
|
"availabilityImpact": "LOW",
|
|
"baseScore": 6.1,
|
|
"baseSeverity": "MEDIUM"
|
|
},
|
|
"exploitabilityScore": 0.8,
|
|
"impactScore": 4.7
|
|
}
|
|
]
|
|
},
|
|
"references": [
|
|
{
|
|
"url": "https://www.insyde.com/security-pledge/SA-2023040",
|
|
"source": "cve@mitre.org"
|
|
}
|
|
]
|
|
} |