CVE-2020-5953
HIGHInsydeH2O UEFI Firmware - Privilege Escalation via SWSMI Handler
Title source: llmDescription
A vulnerability exists in System Management Interrupt (SWSMI) handler of InsydeH2O UEFI Firmware code located in SWSMI handler that dereferences gRT (EFI_RUNTIME_SERVICES) pointer to call a GetVariable service, which is located outside of SMRAM. This can result in code execution in SMM (escalating privilege from ring 0 to ring -2).
References (5)
Core 5
Core References
Product, Vendor Advisory x_refsource_misc
https://www.insyde.com/products
Vendor Advisory x_refsource_misc
https://www.insyde.com/security-pledge
Third Party Advisory x_refsource_confirm
https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20220222-0005/
Third Party Advisory, US Government Resource
https://www.kb.cert.org/vuls/id/796611
Scores
CVSS v3
7.5
EPSS
0.0007
EPSS Percentile
20.3%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Details
Status
published
Products (22)
insyde/insydeh2o
5.12.09.0074
insyde/insydeh2o
5.23.04.0045
insyde/insydeh2o
5.23.45.0023
insyde/insydeh2o
5.33.15.0034
insyde/insydeh2o
5.34.03.0029
insyde/insydeh2o
5.42.03.0010
siemens/ruggedcom_ape1808_firmware
siemens/simatic_field_pg_m5_firmware
siemens/simatic_field_pg_m6_firmware
siemens/simatic_ipc127e_firmware
... and 12 more
Published
Feb 03, 2022
Tracked Since
Feb 18, 2026