CVE-2026-6484

Summary

In an UEFI, Lack of verified boot to certain FV may cause arbitrary code execution.

Affected Software

VendorProductVersion RangeStatus
Insyde SoftwareInsydeH2OSee in the Solutionunknown

Weaknesses

  • CWE-1277: CWE-1277: Insufficient Verification of Data Authenticity in Firmware

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References