Description
An issue was discovered in Insyde InsydeH2O Kernel 5.0 before 05.09.11, 5.1 before 05.17.11, 5.2 before 05.27.11, 5.3 before 05.36.11, 5.4 before 05.44.11, and 5.5 before 05.52.11 affecting FwBlockServiceSmm. Software SMI services that use the Communicate() function of the EFI_SMM_COMMUNICATION_PROTOCOL do not check whether the address of the buffer is valid, which allows use of SMRAM, MMIO, or OS kernel addresses.
References (5)
Core 5
Core References
Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf
Third Party Advisory
https://security.netapp.com/advisory/ntap-20220222-0002/
Vendor Advisory
https://www.insyde.com/security-pledge
Vendor Advisory
https://www.insyde.com/security-pledge/SA-2022022
Third Party Advisory, US Government Resource
https://www.kb.cert.org/vuls/id/796611
Scores
CVSS v3
8.2
EPSS
0.0010
EPSS Percentile
27.6%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Details
CWE
CWE-119
Status
published
Products (15)
insyde/insydeh2o
5.0 - 5.08.29
siemens/simatic_field_pg_m5_firmware
siemens/simatic_field_pg_m6_firmware
siemens/simatic_ipc127e_firmware
siemens/simatic_ipc227g_firmware
siemens/simatic_ipc277g_firmware
siemens/simatic_ipc327g_firmware
siemens/simatic_ipc377g_firmware
siemens/simatic_ipc427e_firmware
siemens/simatic_ipc477e_firmware
... and 5 more
Published
Feb 03, 2022
Tracked Since
Feb 18, 2026