A vulnerability exists in System Management Interrupt (SWSMI) handler of InsydeH2O UEFI Firmware code located in SWSMI handler that dereferences gRT (EFI_RUNTIME_SERVICES) pointer to call a GetVariable service, which is located outside of SMRAM
Published Feb 3, 2022
7.5
HIGHCVSS 3.1
EPSS 0.28%
Description
A vulnerability exists in System Management Interrupt (SWSMI) handler of InsydeH2O UEFI Firmware code located in SWSMI handler that dereferences gRT (EFI_RUNTIME_SERVICES) pointer to call a GetVariable service, which is located outside of SMRAM. This can result in code execution in SMM (escalating privilege from ring 0 to ring -2).
Affected products
No data.
Configuration 1
Configuration 2
- n/a
Running on/with
- n/a
Configuration 3
- n/a
Running on/with
- n/a
Configuration 4
- n/a
Running on/with
- n/a
Configuration 5
- n/a
Running on/with
- n/a
Configuration 6
- n/a
Running on/with
- n/a
Configuration 7
- n/a
Running on/with
- n/a
Configuration 8
- n/a
Running on/with
- n/a
Configuration 9
- n/a
Running on/with
- n/a
Configuration 10
- n/a
Running on/with
- n/a
Configuration 11
- n/a
Running on/with
- n/a
Configuration 12
- n/a
Running on/with
- n/a
Configuration 13
- n/a
Running on/with
- n/a
Configuration 14
- n/a
Running on/with
- n/a
Configuration 15
- n/a
Running on/with
- n/a
Configuration 16
- n/a
Running on/with
- n/a
Configuration 17
- n/a
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
No CWE recorded.
References (7)
- https://cert-portal.siemens.com/productcert/html/ssa-306654.html
- https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf x_refsource_CONFIRMThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-27107 Advisory
- https://security.netapp.com/advisory/ntap-20220222-0005/ x_refsource_CONFIRMThird Party Advisory
- https://www.insyde.com/products x_refsource_MISCProductVendor Advisory
- https://www.insyde.com/security-pledge x_refsource_MISCVendor Advisory
- https://www.kb.cert.org/vuls/id/796611
| Link | Providers | Tags |
|---|---|---|
| https://cert-portal.siemens.com/productcert/html/ssa-306654.html | ||
| https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf | x_refsource_CONFIRMThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-27107 | Advisory | |
| https://security.netapp.com/advisory/ntap-20220222-0005/ | x_refsource_CONFIRMThird Party Advisory | |
| https://www.insyde.com/products | x_refsource_MISCProductVendor Advisory | |
| https://www.insyde.com/security-pledge | x_refsource_MISCVendor Advisory | |
| https://www.kb.cert.org/vuls/id/796611 |
Change history (0)
No recorded changes yet.