![](/assets/img/cve_300x82_sin_bg.png)
CVE-2022-35895
https://notcve.org/view.php?id=CVE-2022-35895
21 Sep 2022 — An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. The FwBlockSericceSmm driver does not properly validate input parameters for a software SMI routine, leading to memory corruption of arbitrary addresses including SMRAM, and possible arbitrary code execution. Se ha detectado un problema en InsydeH2O con el kernel versiones 5.0 hasta 5.5. El controlador FwBlockSericceSmm no comprueba correctamente los parámetros de entrada para una rutina SMI de software, conllevando a una corrupción de... • https://binarly.io/advisories/BRLY-2022-024/index.html • CWE-787: Out-of-bounds Write •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2022-24031
https://notcve.org/view.php?id=CVE-2022-24031
03 Feb 2022 — An issue was discovered in NvmExpressDxe in Insyde InsydeH2O with kernel 5.1 through 5.5. An SMM memory corruption vulnerability allows an attacker to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM. Se ha detectado un problema en NvmExpressDxe en InsydeH2O con kernel versiones 5.1 hasta 5.5. Una vulnerabilidad de corrupción de memoria SMM permite a un atacante escribir datos fijos o predecibles en la SMRAM. • https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf • CWE-787: Out-of-bounds Write •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2021-33625
https://notcve.org/view.php?id=CVE-2021-33625
03 Feb 2022 — An issue was discovered in Kernel 5.x in Insyde InsydeH2O, affecting HddPassword. Software SMI services that use the Communicate() function of the EFI_SMM_COMMUNICATION_PROTOCOL do not check whether the address of the buffer is valid, which allows use of SMRAM, MMIO, or OS kernel addresses. Se ha descubierto un problema en el Kernel versión 5.x de InsydeH2O, que afecta a HddPassword. Los servicios SMI de software que utilizan la función Communicate() del EFI_SMM_COMMUNICATION_PROTOCOL no comprueban si la di... • https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2021-43323
https://notcve.org/view.php?id=CVE-2021-43323
03 Feb 2022 — An issue was discovered in UsbCoreDxe in Insyde InsydeH2O with kernel 5.5 before 05.51.45, 5.4 before 05.43.45, 5.3 before 05.35.45, 5.2 before 05.26.45, 5.1 before 05.16.45, and 5.0 before 05.08.45. An SMM callout vulnerability allows an attacker to hijack execution flow of code running in System Management Mode. Exploiting this issue could lead to escalating privileges to SMM. Se ha detectado un problema en UsbCoreDxe en InsydeH2O con el kernel versiones 5.5 anteriores a 05.51.45, versiones 5.4 anteriores... • https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2021-41838
https://notcve.org/view.php?id=CVE-2021-41838
03 Feb 2022 — An issue was discovered in SdHostDriver in the kernel 5.0 through 5.5 in Insyde InsydeH2O. There is an SMM callout that allows an attacker to access the System Management Mode and execute arbitrary code. This occurs because of a Numeric Range Comparison Without a Minimum Check. Se ha descubierto un problema en SdHostDriver en el kernel versión 5.0 hasta la versión 5.5 en InsydeH2O. Hay una llamada SMM que permite a un atacante acceder al modo de gestión del sistema y ejecutar código arbitrario. • https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2021-42554
https://notcve.org/view.php?id=CVE-2021-42554
03 Feb 2022 — An issue was discovered in Insyde InsydeH2O with Kernel 5.0 before 05.08.42, Kernel 5.1 before 05.16.42, Kernel 5.2 before 05.26.42, Kernel 5.3 before 05.35.42, Kernel 5.4 before 05.42.51, and Kernel 5.5 before 05.50.51. An SMM memory corruption vulnerability in FvbServicesRuntimeDxe allows a possible attacker to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM. Se ha descubierto un problema en InsydeH2O con el Kernel versión 5.0 antes de 05.08.42, e... • https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf • CWE-787: Out-of-bounds Write •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2021-41839
https://notcve.org/view.php?id=CVE-2021-41839
03 Feb 2022 — An issue was discovered in NvmExpressDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. Because of an Untrusted Pointer Dereference that causes SMM memory corruption, an attacker may be able to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM. Se ha descubierto un problema en NvmExpressDxe en el kernel versión 5.0 hasta la versión 5.5 de InsydeH2O. Debido a una desviación de puntero no fiable que provoca la corrupción de la memoria de SMM, un ata... • https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2021-41837
https://notcve.org/view.php?id=CVE-2021-41837
03 Feb 2022 — An issue was discovered in AhciBusDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. Because of an Untrusted Pointer Dereference that causes SMM memory corruption, an attacker may be able to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM. Se descubrió un problema en AhciBusDxe en el kernel versión 5.0 hasta la versión 5.5 en InsydeH2O. Debido a una desviación de puntero no fiable que provoca la corrupción de la memoria de SMM, un atacante puede... • https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2022-24030
https://notcve.org/view.php?id=CVE-2022-24030
03 Feb 2022 — An issue was discovered in AhciBusDxe in Insyde InsydeH2O with kernel 5.1 through 5.5. An SMM memory corruption vulnerability allows an attacker to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM. Se ha descubierto un problema en AhciBusDxe en InsydeH2O con el kernel versión 5.1 hasta la versión 5.5. Una vulnerabilidad de corrupción de memoria en SMM permite a un atacante escribir datos fijos o predecibles en SMRAM. • https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf • CWE-787: Out-of-bounds Write •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2021-41841
https://notcve.org/view.php?id=CVE-2021-41841
03 Feb 2022 — An issue was discovered in AhciBusDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. There is an SMM callout that allows an attacker to access the System Management Mode and execute arbitrary code. This occurs because of Inclusion of Functionality from an Untrusted Control Sphere. Se ha descubierto un problema en AhciBusDxe en el kernel versión 5.0 hasta la 5.5 de InsydeH2O. Hay una llamada SMM que permite a un atacante acceder al Modo de Gestión del Sistema y ejecutar código arbitrario. • https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf • CWE-829: Inclusion of Functionality from Untrusted Control Sphere •