Description
An issue was discovered in Kernel 5.x in Insyde InsydeH2O, affecting HddPassword. Software SMI services that use the Communicate() function of the EFI_SMM_COMMUNICATION_PROTOCOL do not check whether the address of the buffer is valid, which allows use of SMRAM, MMIO, or OS kernel addresses.
References (5)
Core 5
Core References
Vendor Advisory x_refsource_misc
https://www.insyde.com/security-pledge
Vendor Advisory x_refsource_misc
https://www.insyde.com/security-pledge/SA-2022014
Third Party Advisory x_refsource_confirm
https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20220222-0004/
Third Party Advisory, US Government Resource
https://www.kb.cert.org/vuls/id/796611
Scores
CVSS v3
7.5
EPSS
0.0006
EPSS Percentile
19.5%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Details
CWE
CWE-119
Status
published
Products (18)
insyde/insydeh2o
5.1 - 5.16.23
netapp/fas\/aff_bios
siemens/ruggedcom_ape1808_firmware
siemens/simatic_field_pg_m5_firmware
siemens/simatic_field_pg_m6_firmware
siemens/simatic_ipc127e_firmware
siemens/simatic_ipc227g_firmware
siemens/simatic_ipc277g_firmware
siemens/simatic_ipc327g_firmware
siemens/simatic_ipc377g_firmware
... and 8 more
Published
Feb 03, 2022
Tracked Since
Feb 18, 2026