CVE-2021-33627
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered in Insyde InsydeH2O Kernel 5.0 before 05.09.11, 5.1 before 05.17.11, 5.2 before 05.27.11, 5.3 before 05.36.11, 5.4 before 05.44.11, and 5.5 before 05.52.11 affecting FwBlockServiceSmm. Software SMI services that use the Communicate() function of the EFI_SMM_COMMUNICATION_PROTOCOL do not check whether the address of the buffer is valid, which allows use of SMRAM, MMIO, or OS kernel addresses.
Se ha descubierto un problema en InsydeH2O versión 5.x, que afecta a FwBlockServiceSmm. Los servicios SMI de software que utilizan la función Communicate() del EFI_SMM_COMMUNICATION_PROTOCOL no comprueban si la dirección del búfer es válida, lo que permite el uso de direcciones SMRAM, MMIO o del núcleo del SO
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-05-28 CVE Reserved
- 2022-02-03 CVE Published
- 2023-09-24 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf | Third Party Advisory | |
https://security.netapp.com/advisory/ntap-20220222-0002 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.insyde.com/security-pledge | 2024-07-22 | |
https://www.insyde.com/security-pledge/SA-2022022 | 2024-07-22 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Siemens Search vendor "Siemens" | Simatic Field Pg M5 Firmware Search vendor "Siemens" for product "Simatic Field Pg M5 Firmware" | * | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Field Pg M5 Search vendor "Siemens" for product "Simatic Field Pg M5" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Field Pg M6 Firmware Search vendor "Siemens" for product "Simatic Field Pg M6 Firmware" | * | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Field Pg M6 Search vendor "Siemens" for product "Simatic Field Pg M6" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Ipc127e Firmware Search vendor "Siemens" for product "Simatic Ipc127e Firmware" | * | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Ipc127e Search vendor "Siemens" for product "Simatic Ipc127e" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Ipc227g Firmware Search vendor "Siemens" for product "Simatic Ipc227g Firmware" | * | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Ipc227g Search vendor "Siemens" for product "Simatic Ipc227g" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Ipc277g Firmware Search vendor "Siemens" for product "Simatic Ipc277g Firmware" | * | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Ipc277g Search vendor "Siemens" for product "Simatic Ipc277g" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Ipc327g Firmware Search vendor "Siemens" for product "Simatic Ipc327g Firmware" | * | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Ipc327g Search vendor "Siemens" for product "Simatic Ipc327g" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Ipc377g Firmware Search vendor "Siemens" for product "Simatic Ipc377g Firmware" | * | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Ipc377g Search vendor "Siemens" for product "Simatic Ipc377g" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Ipc427e Firmware Search vendor "Siemens" for product "Simatic Ipc427e Firmware" | * | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Ipc427e Search vendor "Siemens" for product "Simatic Ipc427e" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Ipc477e Firmware Search vendor "Siemens" for product "Simatic Ipc477e Firmware" | * | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Ipc477e Search vendor "Siemens" for product "Simatic Ipc477e" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Ipc627e Firmware Search vendor "Siemens" for product "Simatic Ipc627e Firmware" | * | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Ipc627e Search vendor "Siemens" for product "Simatic Ipc627e" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Ipc647e Firmware Search vendor "Siemens" for product "Simatic Ipc647e Firmware" | * | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Ipc647e Search vendor "Siemens" for product "Simatic Ipc647e" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Ipc677e Firmware Search vendor "Siemens" for product "Simatic Ipc677e Firmware" | * | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Ipc677e Search vendor "Siemens" for product "Simatic Ipc677e" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Ipc847e Firmware Search vendor "Siemens" for product "Simatic Ipc847e Firmware" | * | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Ipc847e Search vendor "Siemens" for product "Simatic Ipc847e" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Itp1000 Firmware Search vendor "Siemens" for product "Simatic Itp1000 Firmware" | * | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Itp1000 Search vendor "Siemens" for product "Simatic Itp1000" | - | - |
Safe
|
Insyde Search vendor "Insyde" | Insydeh2o Search vendor "Insyde" for product "Insydeh2o" | >= 5.0 < 5.08.29 Search vendor "Insyde" for product "Insydeh2o" and version " >= 5.0 < 5.08.29" | - |
Affected
| ||||||
Insyde Search vendor "Insyde" | Insydeh2o Search vendor "Insyde" for product "Insydeh2o" | >= 5.1 < 5.16.29 Search vendor "Insyde" for product "Insydeh2o" and version " >= 5.1 < 5.16.29" | - |
Affected
| ||||||
Insyde Search vendor "Insyde" | Insydeh2o Search vendor "Insyde" for product "Insydeh2o" | >= 5.2 < 5.26.29 Search vendor "Insyde" for product "Insydeh2o" and version " >= 5.2 < 5.26.29" | - |
Affected
| ||||||
Insyde Search vendor "Insyde" | Insydeh2o Search vendor "Insyde" for product "Insydeh2o" | >= 5.3 < 5.35.29 Search vendor "Insyde" for product "Insydeh2o" and version " >= 5.3 < 5.35.29" | - |
Affected
|