CVE-2021-41837
HIGHInsyde InsydeH2O 5.0-5.5 - Untrusted Pointer Dereference in AhciBusDxe
Title source: llmDescription
An issue was discovered in AhciBusDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. Because of an Untrusted Pointer Dereference that causes SMM memory corruption, an attacker may be able to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM.
References (5)
Core 5
Core References
Vendor Advisory x_refsource_misc
https://www.insyde.com/security-pledge/SA-2022024
Third Party Advisory x_refsource_confirm
https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20220222-0003/
Third Party Advisory, US Government Resource
https://www.kb.cert.org/vuls/id/796611
Vendor Advisory x_refsource_misc
https://www.insyde.com/security-pledge
Scores
CVSS v3
8.2
EPSS
0.0006
EPSS Percentile
19.6%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Details
CWE
CWE-119
Status
published
Products (15)
insyde/insydeh2o
5.0 - 5.08.41
siemens/simatic_field_pg_m5_firmware
siemens/simatic_field_pg_m6_firmware
siemens/simatic_ipc127e_firmware
siemens/simatic_ipc227g_firmware
siemens/simatic_ipc277g_firmware
siemens/simatic_ipc327g_firmware
siemens/simatic_ipc377g_firmware
siemens/simatic_ipc427e_firmware
siemens/simatic_ipc477e_firmware
... and 5 more
Published
Feb 03, 2022
Tracked Since
Feb 18, 2026