Insyde Software develops firmware and UEFI-level components that are embedded across a wide range of laptop, desktop, and embedded systems from original equipment manufacturers, giving its vulnerabilities prominence disproportionate to its narrow product count. The vendor's disclosure footprint concentrates in its InsydeH2O firmware platform and related kernel and runtime components, where a well-represented volume of vulnerabilities recurs around concurrency weaknesses, memory-safety issues, and input-validation flaws that are characteristic of low-level firmware code operating with elevated privilege. While the severity distribution leans toward lower outcomes, the structural significance of firmware-layer exposure means that even moderate-severity flaws in these components can enable persistent access, privilege escalation, or system compromise across OEM product lines that may remain in service for years. Defenders should treat Insyde disclosures as critical to inventory and patch planning for any managed fleet, since firmware updates depend on device vendor coordination and are often delayed or never released; current CVE counts, severity breakdown, and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Insyde Software over time
Of all the CVEs published by Insyde Software as a CNA, 0.0% affect products that Insyde Software develops as a vendor.
Of all the CVEs published that affect products developed by Insyde Software, 0.0% are self-published by Insyde Software as a CNA.
Signals from CVEs in this vendor scope (104 CVEs).
104 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-38578CRITICAL Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize. | Mar 3, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-41842CRITICAL An issue was discovered in AtaLegacySmm in the kernel 5.0 before 05.08.46, 5.1 before 05.16.46, 5.2 before 05.26.46, 5.3 before 05.35.46, 5.4 before 05.43.46, and 5.5 before 05.51. | Jan 6, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-30771HIGH Initialization function in PnpSmm could lead to SMRAM corruption when using subsequent PNP SMI functions Initialization function in PnpSmm could lead to SMRAM corruption when using | Nov 15, 2022 | 8.2 | 27 | NO | NO |
CVE-2021-42554HIGH An issue was discovered in Insyde InsydeH2O with Kernel 5.0 before 05.08.42, Kernel 5.1 before 05.16.42, Kernel 5.2 before 05.26.42, Kernel 5.3 before 05.35.42, Kernel 5.4 before 0 | Feb 3, 2022 | 8.2 | 27 | NO | NO |
CVE-2023-39281CRITICAL A stack buffer overflow vulnerability discovered in AsfSecureBootDxe in Insyde InsydeH2O with kernel 5.0 through 5.5 allows attackers to run arbitrary code execution during the DXE | Nov 1, 2023 | 9.8 | 26 | NO | NO |
CVE-2023-22613HIGH An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. It is possible to write to an attacker-controlled address. An attacker could invoke an SMI hand | Apr 11, 2023 | 8.8 | 26 | NO | NO |
CVE-2023-22614HIGH An issue was discovered in ChipsetSvcSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. There is insufficient input validation in BIOS Guard updates. An attacker can induce memor | Apr 11, 2023 | 8.8 | 26 | NO | NO |
CVE-2023-22612HIGH An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. A malicious host OS can invoke an Insyde SMI handler with malformed arguments, resulting in mem | Apr 11, 2023 | 8.8 | 26 | NO | NO |
CVE-2022-36337HIGH An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. A stack buffer overflow vulnerability in the MebxConfiguration driver leads to arbitrary code execution. Co | Nov 23, 2022 | 8.2 | 26 | NO | NO |
CVE-2022-29276HIGH SMI functions in AhciBusDxe use untrusted inputs leading to corruption of SMRAM. SMI functions in AhciBusDxe use untrusted inputs leading to corruption of SMRAM. This issue was dis | Nov 15, 2022 | 8.2 | 26 | NO | NO |
Signals from CVEs in this vendor scope (104 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Insyde Software.
Media articles that mention a CVE ID that affects a product developed by Insyde Software — matched by CVE ID, not by vendor name.