Insyde Product Security Update Advisory (CVE-2023-39284)

Overview

 

Insyde has made available an update that addresses a vulnerability in their product. users of affected versions are advised to update to the latest version.

 

Affected Products

 

insyde insydeh2o

  • 5.2 or later and prior to 5.2.05.28.33
  • 5.3 or later and prior to 5.3.05.37.33
  • 5.4 or later and prior to 5.4.05.45.33
  • 5.5 or later and prior to 5.5.05.53.33
  • 5.6 or later and prior to 5.6.05.60.33

 

Resolved Vulnerabilities

 

Arbitrary call to SetVariable with uncleaned arguments in SMI handler vulnerability (CVE-2023-39284)

 

Vulnerability Patches

 

vulnerability Patches were made available in the October 1, 2023 update. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

kernel 5.2: version 05.28.33
kernel 5.3: version 05.37.33
kernel 5.4: version 05.45.33
kernel 5.5: version 05.53.33
kernel 5.6: Version 05.60.33

 

Referenced Sites

 

[1] CVE-2023-39284 Detail
https://nvd.nist.gov/vuln/detail/CVE-2023-39284#range-10037308l

[2] Insyde Security Advisory 2023056

https://www.insyde.com/security-pledge/SA-2023056

[3] Insyde’s Security Pledge

https://www.insyde.com/security-pledge