Vulnerabilidades em Insyde Software
21 resultadosAnálise Vexday
A Insyde Software acumula 15 vulnerabilidades no histórico, predominantly relacionadas a buffer overflow (CWE-787), porém nenhuma sob exploração ativa documentada ou com severidade crítica. O panorama atual não apresenta vulnerabilidades recentes (últimos 90 dias), indicando risco residual baixo no curto prazo, embora a natureza das fraquezas históricas (escrita de memória) demande atenção em integrações legadas.
CVE-2025-4275HIGHSecureFlashDxe: Incorrect UEFI variable attributes check allows usage of invalid certificateEPSS 0.4%CVE-2025-4421HIGHEfiSmiServices: gEfiSmmCpuProtocol, SMM memory corruption vulnerabilities in SMM moduleEPSS 0.3%CVE-2025-4422HIGHEfiSmiServices : EfiPcdProtocol, SMM memory corruption vulnerabilities in SMM moduleEPSS 0.2%CVE-2025-4426MEDIUMSetupAutomationSmm : SMRAM memory contents leak / information disclosure vulnerability in SMM moduleEPSS 0.2%CVE-2025-4425HIGHSetupAutomationSmm: Stack overflow vulnerability in SMI handlerEPSS 0.2%CVE-2025-4423HIGHSetupAutomationSmm:Vulnerability in the SMM module allow attacker to write arbitrary code and lead to memory corruptionEPSS 0.2%CVE-2025-4424MEDIUMSetupAutomationSmm : Arbitrary calls to SmmSetVariable with unsanitised arguments in SMI handlerEPSS 0.2%CVE-2025-12050HIGHIn H2OFFT32.sys is potentially vulnerable to a buffer overflow.EPSS 0.2%CVE-2025-12051HIGHH2OFFT64.sys is potentially vulnerable to a buffer overflow.EPSS 0.2%CVE-2025-12053HIGHegwindrvx64.sys is potentially vulnerable to a buffer overflowEPSS 0.1%CVE-2025-12052HIGHegwindrv.sys is potentially vulnerable to a buffer overflow.EPSS 0.1%CVE-2025-10451HIGHH19Int15CallbackSmm: SMM memory corruption vulnerability in combined DXE/SMM (SMRAM write)EPSS 0.1%CVE-2026-6484HIGHLack of verified boot to certain FV may cause arbitrary code executionEPSS 0.1%CVE-2025-4276HIGHUsbCoreDxe: improper input validation may lead to arbitrary code executionEPSS 0.1%CVE-2025-4277HIGHTcg2Smm: improper input validation may lead to arbitrary code executionEPSS 0.1%CVE-2021-43614MEDIUMVariableEditSmm: Error checking of UEFI variables could cause buffer overflow, leading to code executionEPSS 0.1%CVE-2025-4410HIGHSetupUtility: A buffer overflow vulnerability leads to arbitrary code execution.EPSS 0.1%CVE-2021-38489HIGHHDD Password Stored In PlaintextEPSS 0.1%CVE-2026-9805LOWFMTSWriteUseIntelLib: FMTS SMM IHISI Buffer OverflowEPSS 0.1%CVE-2021-43613MEDIUMSysPasswordDxe: Password hashes are exposed in runtime UEFI variables, leading to escalation of privilegeEPSS 0.1%