CVE-2021-42554

HIGH

Insyde InsydeH2O Kernel 5.0-5.5 - Out-of-bounds Write in FvbServicesRuntimeDxe

Title source: llm
STIX 2.1

Description

An issue was discovered in Insyde InsydeH2O with Kernel 5.0 before 05.08.42, Kernel 5.1 before 05.16.42, Kernel 5.2 before 05.26.42, Kernel 5.3 before 05.35.42, Kernel 5.4 before 05.42.51, and Kernel 5.5 before 05.50.51. An SMM memory corruption vulnerability in FvbServicesRuntimeDxe allows a possible attacker to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM.

References (5)

Core 5
Core References
Vendor Advisory x_refsource_misc
https://www.insyde.com/security-pledge
Vendor Advisory x_refsource_misc
https://www.insyde.com/security-pledge/SA-2022012
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20220216-0007/
Third Party Advisory x_refsource_confirm
https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf
Third Party Advisory, US Government Resource
https://www.kb.cert.org/vuls/id/796611

Scores

CVSS v3 8.2
EPSS 0.0009
EPSS Percentile 25.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-787
Status published
Products (16)
insyde/insydeh2o 5.0 - 5.08.42
siemens/ruggedcom_ape1808_firmware
siemens/simatic_field_pg_m5_firmware
siemens/simatic_field_pg_m6_firmware
siemens/simatic_ipc127e_firmware
siemens/simatic_ipc227g_firmware
siemens/simatic_ipc277g_firmware
siemens/simatic_ipc327g_firmware
siemens/simatic_ipc377g_firmware
siemens/simatic_ipc427e_firmware
... and 6 more
Published Feb 03, 2022
Tracked Since Feb 18, 2026