CVE-2020-5953
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability exists in System Management Interrupt (SWSMI) handler of InsydeH2O UEFI Firmware code located in SWSMI handler that dereferences gRT (EFI_RUNTIME_SERVICES) pointer to call a GetVariable service, which is located outside of SMRAM. This can result in code execution in SMM (escalating privilege from ring 0 to ring -2).
Se presenta una vulnerabilidad en el manejador de Interrupciones de administración del Sistema (SWSMI) del código del Firmware UEFI de InsydeH2O ubicado en el manejador SWSMI que desreferencia el puntero gRT (EFI_RUNTIME_SERVICES) para llamar a un servicio GetVariable, que es encontrado fuera de la SMRAM. Esto puede resultar en una ejecución de código en SMM (escalando el privilegio del anillo 0 al anillo -2)
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-01-06 CVE Reserved
- 2022-02-03 CVE Published
- 2023-09-24 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf | Third Party Advisory | |
https://security.netapp.com/advisory/ntap-20220222-0005 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.insyde.com/products | 2022-04-12 | |
https://www.insyde.com/security-pledge | 2022-04-12 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Siemens Search vendor "Siemens" | Ruggedcom Ape1808 Firmware Search vendor "Siemens" for product "Ruggedcom Ape1808 Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Ruggedcom Ape1808 Search vendor "Siemens" for product "Ruggedcom Ape1808" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Field Pg M6 Firmware Search vendor "Siemens" for product "Simatic Field Pg M6 Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Field Pg M6 Search vendor "Siemens" for product "Simatic Field Pg M6" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Ipc127e Firmware Search vendor "Siemens" for product "Simatic Ipc127e Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Ipc127e Search vendor "Siemens" for product "Simatic Ipc127e" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Ipc227g Firmware Search vendor "Siemens" for product "Simatic Ipc227g Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Ipc227g Search vendor "Siemens" for product "Simatic Ipc227g" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Ipc277g Firmware Search vendor "Siemens" for product "Simatic Ipc277g Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Ipc277g Search vendor "Siemens" for product "Simatic Ipc277g" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Itp1000 Firmware Search vendor "Siemens" for product "Simatic Itp1000 Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Itp1000 Search vendor "Siemens" for product "Simatic Itp1000" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Ipc477e Pro Firmware Search vendor "Siemens" for product "Simatic Ipc477e Pro Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Ipc477e Pro Search vendor "Siemens" for product "Simatic Ipc477e Pro" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Ipc627e Firmware Search vendor "Siemens" for product "Simatic Ipc627e Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Ipc627e Search vendor "Siemens" for product "Simatic Ipc627e" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Ipc647e Firmware Search vendor "Siemens" for product "Simatic Ipc647e Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Ipc647e Search vendor "Siemens" for product "Simatic Ipc647e" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Ipc677e Firmware Search vendor "Siemens" for product "Simatic Ipc677e Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Ipc677e Search vendor "Siemens" for product "Simatic Ipc677e" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Ipc847e Firmware Search vendor "Siemens" for product "Simatic Ipc847e Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Ipc847e Search vendor "Siemens" for product "Simatic Ipc847e" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Ipc327g Firmware Search vendor "Siemens" for product "Simatic Ipc327g Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Ipc327g Search vendor "Siemens" for product "Simatic Ipc327g" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Ipc377g Firmware Search vendor "Siemens" for product "Simatic Ipc377g Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Ipc377g Search vendor "Siemens" for product "Simatic Ipc377g" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Ipc427e Firmware Search vendor "Siemens" for product "Simatic Ipc427e Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Ipc427e Search vendor "Siemens" for product "Simatic Ipc427e" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Ipc477e Firmware Search vendor "Siemens" for product "Simatic Ipc477e Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Ipc477e Search vendor "Siemens" for product "Simatic Ipc477e" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Field Pg M5 Firmware Search vendor "Siemens" for product "Simatic Field Pg M5 Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Field Pg M5 Search vendor "Siemens" for product "Simatic Field Pg M5" | - | - |
Safe
|
Insyde Search vendor "Insyde" | Insydeh2o Search vendor "Insyde" for product "Insydeh2o" | 5.12.09.0074 Search vendor "Insyde" for product "Insydeh2o" and version "5.12.09.0074" | - |
Affected
| ||||||
Insyde Search vendor "Insyde" | Insydeh2o Search vendor "Insyde" for product "Insydeh2o" | 5.23.04.0045 Search vendor "Insyde" for product "Insydeh2o" and version "5.23.04.0045" | - |
Affected
| ||||||
Insyde Search vendor "Insyde" | Insydeh2o Search vendor "Insyde" for product "Insydeh2o" | 5.23.45.0023 Search vendor "Insyde" for product "Insydeh2o" and version "5.23.45.0023" | - |
Affected
| ||||||
Insyde Search vendor "Insyde" | Insydeh2o Search vendor "Insyde" for product "Insydeh2o" | 5.33.15.0034 Search vendor "Insyde" for product "Insydeh2o" and version "5.33.15.0034" | - |
Affected
| ||||||
Insyde Search vendor "Insyde" | Insydeh2o Search vendor "Insyde" for product "Insydeh2o" | 5.34.03.0029 Search vendor "Insyde" for product "Insydeh2o" and version "5.34.03.0029" | - |
Affected
| ||||||
Insyde Search vendor "Insyde" | Insydeh2o Search vendor "Insyde" for product "Insydeh2o" | 5.42.03.0010 Search vendor "Insyde" for product "Insydeh2o" and version "5.42.03.0010" | - |
Affected
|