Security Advisory
CVE-2023-39284
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
An issue was discovered in IhisiServicesSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. There are arbitrary calls to SetVariable with unsanitized arguments in the SMI handler.