CVE-2021-33625

HIGH

InsydeH2O Kernel 5.x - Use After Free

Title source: llm
STIX 2.1

Description

An issue was discovered in Kernel 5.x in Insyde InsydeH2O, affecting HddPassword. Software SMI services that use the Communicate() function of the EFI_SMM_COMMUNICATION_PROTOCOL do not check whether the address of the buffer is valid, which allows use of SMRAM, MMIO, or OS kernel addresses.

References (5)

Core 5
Core References
Vendor Advisory x_refsource_misc
https://www.insyde.com/security-pledge
Vendor Advisory x_refsource_misc
https://www.insyde.com/security-pledge/SA-2022014
Third Party Advisory x_refsource_confirm
https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20220222-0004/
Third Party Advisory, US Government Resource
https://www.kb.cert.org/vuls/id/796611

Scores

CVSS v3 7.5
EPSS 0.0006
EPSS Percentile 19.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (18)
insyde/insydeh2o 5.1 - 5.16.23
netapp/fas\/aff_bios
siemens/ruggedcom_ape1808_firmware
siemens/simatic_field_pg_m5_firmware
siemens/simatic_field_pg_m6_firmware
siemens/simatic_ipc127e_firmware
siemens/simatic_ipc227g_firmware
siemens/simatic_ipc277g_firmware
siemens/simatic_ipc327g_firmware
siemens/simatic_ipc377g_firmware
... and 8 more
Published Feb 03, 2022
Tracked Since Feb 18, 2026