CVE-2022-32955 | InsydeH2O up to 5.5 NvmExpressDxe toctou (EUVD-2022-36021)
A vulnerability marked as problematic has been reported in InsydeH2O up to 5.5. Affected by this issue is some unknown functionality of the component NvmExpressDxe. The manipulation leads to time-of-check time-of-use.
This vulnerability is uniquely identified as CVE-2022-32955. The attack can only be initiated within the local network. No exploit exists.