CVE-2021-33625
 
Severity Score
7.5
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
An issue was discovered in Kernel 5.x in Insyde InsydeH2O, affecting HddPassword. Software SMI services that use the Communicate() function of the EFI_SMM_COMMUNICATION_PROTOCOL do not check whether the address of the buffer is valid, which allows use of SMRAM, MMIO, or OS kernel addresses.
Se ha descubierto un problema en el Kernel versión 5.x de InsydeH2O, que afecta a HddPassword. Los servicios SMI de software que utilizan la función Communicate() del EFI_SMM_COMMUNICATION_PROTOCOL no comprueban si la dirección del búfer es válida, lo que permite el uso de direcciones de SMRAM, MMIO o del núcleo del SO
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2021-05-28 CVE Reserved
- 2022-02-03 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf | Third Party Advisory | |
https://security.netapp.com/advisory/ntap-20220222-0004 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.insyde.com/security-pledge | 2022-04-12 | |
https://www.insyde.com/security-pledge/SA-2022014 | 2022-04-12 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Siemens Search vendor "Siemens" | Ruggedcom Ape1808 Firmware Search vendor "Siemens" for product "Ruggedcom Ape1808 Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Ruggedcom Ape1808 Search vendor "Siemens" for product "Ruggedcom Ape1808" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Field Pg M5 Firmware Search vendor "Siemens" for product "Simatic Field Pg M5 Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Field Pg M5 Search vendor "Siemens" for product "Simatic Field Pg M5" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Ipc127e Firmware Search vendor "Siemens" for product "Simatic Ipc127e Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Ipc127e Search vendor "Siemens" for product "Simatic Ipc127e" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Itp1000 Firmware Search vendor "Siemens" for product "Simatic Itp1000 Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Itp1000 Search vendor "Siemens" for product "Simatic Itp1000" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Ipc277g Firmware Search vendor "Siemens" for product "Simatic Ipc277g Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Ipc277g Search vendor "Siemens" for product "Simatic Ipc277g" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Ipc227g Firmware Search vendor "Siemens" for product "Simatic Ipc227g Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Ipc227g Search vendor "Siemens" for product "Simatic Ipc227g" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Ipc327g Firmware Search vendor "Siemens" for product "Simatic Ipc327g Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Ipc327g Search vendor "Siemens" for product "Simatic Ipc327g" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Ipc377g Firmware Search vendor "Siemens" for product "Simatic Ipc377g Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Ipc377g Search vendor "Siemens" for product "Simatic Ipc377g" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Ipc427e Firmware Search vendor "Siemens" for product "Simatic Ipc427e Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Ipc427e Search vendor "Siemens" for product "Simatic Ipc427e" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Ipc477e Firmware Search vendor "Siemens" for product "Simatic Ipc477e Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Ipc477e Search vendor "Siemens" for product "Simatic Ipc477e" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Ipc477e Pro Firmware Search vendor "Siemens" for product "Simatic Ipc477e Pro Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Ipc477e Pro Search vendor "Siemens" for product "Simatic Ipc477e Pro" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Ipc627e Firmware Search vendor "Siemens" for product "Simatic Ipc627e Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Ipc627e Search vendor "Siemens" for product "Simatic Ipc627e" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Ipc647e Firmware Search vendor "Siemens" for product "Simatic Ipc647e Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Ipc647e Search vendor "Siemens" for product "Simatic Ipc647e" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Ipc677e Firmware Search vendor "Siemens" for product "Simatic Ipc677e Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Ipc677e Search vendor "Siemens" for product "Simatic Ipc677e" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Ipc847e Firmware Search vendor "Siemens" for product "Simatic Ipc847e Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Ipc847e Search vendor "Siemens" for product "Simatic Ipc847e" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Field Pg M6 Firmware Search vendor "Siemens" for product "Simatic Field Pg M6 Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Field Pg M6 Search vendor "Siemens" for product "Simatic Field Pg M6" | - | - |
Safe
|
Insyde Search vendor "Insyde" | Insydeh2o Search vendor "Insyde" for product "Insydeh2o" | >= 5.1 < 5.16.23 Search vendor "Insyde" for product "Insydeh2o" and version " >= 5.1 < 5.16.23" | - |
Affected
| ||||||
Insyde Search vendor "Insyde" | Insydeh2o Search vendor "Insyde" for product "Insydeh2o" | >= 5.2 < 5.26.23 Search vendor "Insyde" for product "Insydeh2o" and version " >= 5.2 < 5.26.23" | - |
Affected
| ||||||
Insyde Search vendor "Insyde" | Insydeh2o Search vendor "Insyde" for product "Insydeh2o" | >= 5.3 < 5.35.23 Search vendor "Insyde" for product "Insydeh2o" and version " >= 5.3 < 5.35.23" | - |
Affected
| ||||||
Insyde Search vendor "Insyde" | Insydeh2o Search vendor "Insyde" for product "Insydeh2o" | >= 5.4 < 5.43.22 Search vendor "Insyde" for product "Insydeh2o" and version " >= 5.4 < 5.43.22" | - |
Affected
| ||||||
Insyde Search vendor "Insyde" | Insydeh2o Search vendor "Insyde" for product "Insydeh2o" | >= 5.5 < 5.51.22 Search vendor "Insyde" for product "Insydeh2o" and version " >= 5.5 < 5.51.22" | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Fas\/aff Bios Search vendor "Netapp" for product "Fas\/aff Bios" | - | - |
Affected
|