Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Insyde Software

First CVE: Dec 11, 2005Active for: 21 yearsTotal CVEs: 104
28.3
VTI Score
Low

Insyde Software develops firmware and UEFI-level components that are embedded across a wide range of laptop, desktop, and embedded systems from original equipment manufacturers, giving its vulnerabilities prominence disproportionate to its narrow product count. The vendor's disclosure footprint concentrates in its InsydeH2O firmware platform and related kernel and runtime components, where a well-represented volume of vulnerabilities recurs around concurrency weaknesses, memory-safety issues, and input-validation flaws that are characteristic of low-level firmware code operating with elevated privilege. While the severity distribution leans toward lower outcomes, the structural significance of firmware-layer exposure means that even moderate-severity flaws in these components can enable persistent access, privilege escalation, or system compromise across OEM product lines that may remain in service for years. Defenders should treat Insyde disclosures as critical to inventory and patch planning for any managed fleet, since firmware updates depend on device vendor coordination and are often delayed or never released; current CVE counts, severity breakdown, and exploitation activity are shown alongside this summary.

FAUCET AI Generated
104
Total CVEs
More Total CVEs than 99% of tracked vendors
1.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
7.3
Avg CVSS Score
Higher Avg CVSS Score than 55% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Insyde Software over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 11, 2005
20 years ago
Most Recent CVE
Jun 12, 2025
407 days ago

Self-Reporting Analysis

Of all the CVEs published by Insyde Software as a CNA, 0.0% affect products that Insyde Software develops as a vendor.

100.0%
Self-reported: 0 (0.0%)
Third-party: 15 (100.0%)

Of all the CVEs published that affect products developed by Insyde Software, 0.0% are self-published by Insyde Software as a CNA.

100.0%
Self-published: 0 (0.0%)
Other CNAs: 104 (100.0%)

Products(12 total)

Top CVEs

Signals from CVEs in this vendor scope (104 CVEs).

104 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-38578CRITICAL
Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize.
Mar 3, 20229.831NONO
CVE-2021-41842CRITICAL
An issue was discovered in AtaLegacySmm in the kernel 5.0 before 05.08.46, 5.1 before 05.16.46, 5.2 before 05.26.46, 5.3 before 05.35.46, 5.4 before 05.43.46, and 5.5 before 05.51.
Jan 6, 20229.830NONO
CVE-2022-30771HIGH
Initialization function in PnpSmm could lead to SMRAM corruption when using subsequent PNP SMI functions Initialization function in PnpSmm could lead to SMRAM corruption when using
Nov 15, 20228.227NONO
CVE-2021-42554HIGH
An issue was discovered in Insyde InsydeH2O with Kernel 5.0 before 05.08.42, Kernel 5.1 before 05.16.42, Kernel 5.2 before 05.26.42, Kernel 5.3 before 05.35.42, Kernel 5.4 before 0
Feb 3, 20228.227NONO
CVE-2023-39281CRITICAL
A stack buffer overflow vulnerability discovered in AsfSecureBootDxe in Insyde InsydeH2O with kernel 5.0 through 5.5 allows attackers to run arbitrary code execution during the DXE
Nov 1, 20239.826NONO
CVE-2023-22613HIGH
An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. It is possible to write to an attacker-controlled address. An attacker could invoke an SMI hand
Apr 11, 20238.826NONO
CVE-2023-22614HIGH
An issue was discovered in ChipsetSvcSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. There is insufficient input validation in BIOS Guard updates. An attacker can induce memor
Apr 11, 20238.826NONO
CVE-2023-22612HIGH
An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. A malicious host OS can invoke an Insyde SMI handler with malformed arguments, resulting in mem
Apr 11, 20238.826NONO
CVE-2022-36337HIGH
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. A stack buffer overflow vulnerability in the MebxConfiguration driver leads to arbitrary code execution. Co
Nov 23, 20228.226NONO
CVE-2022-29276HIGH
SMI functions in AhciBusDxe use untrusted inputs leading to corruption of SMRAM. SMI functions in AhciBusDxe use untrusted inputs leading to corruption of SMRAM. This issue was dis
Nov 15, 20228.226NONO
View all 104 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products104 CVEs
25%
70%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local90 (86.5%)
Network11 (10.6%)
Unknown1 (1.0%)
Physical2 (1.9%)
Adjacent Network0 (0.0%)
Attack Complexity
Low63 (60.6%)
High40 (38.5%)
Unknown1 (1.0%)
User Interaction
None102 (98.1%)
Unknown1 (1.0%)
Required1 (1.0%)
Privileges Required
Low40 (38.5%)
High51 (49.0%)
None12 (11.5%)
Unknown1 (1.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (104 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Insyde Software.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Insyde Software — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Insyde Software's Products

View all 2 CNAs →

Top CWEs