First published: Thu Feb 03 2022(Updated: )
A vulnerability exists in System Management Interrupt (SWSMI) handler of InsydeH2O UEFI Firmware code located in SWSMI handler that dereferences gRT (EFI_RUNTIME_SERVICES) pointer to call a GetVariable service, which is located outside of SMRAM. This can result in code execution in SMM (escalating privilege from ring 0 to ring -2).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Insyde InsydeH2O | =5.12.09.0074 | |
Insyde InsydeH2O | =5.23.04.0045 | |
Insyde InsydeH2O | =5.23.45.0023 | |
Insyde InsydeH2O | =5.33.15.0034 | |
Insyde InsydeH2O | =5.34.03.0029 | |
Insyde InsydeH2O | =5.42.03.0010 | |
Siemens Ruggedcom Ape1808 Firmware | ||
Siemens Ruggedcom Ape1808 | ||
Siemens Simatic Field Pg M6 Firmware | ||
Siemens Simatic Field Pg M6 | ||
Siemens Simatic Ipc127e Firmware | ||
Siemens Simatic Ipc127e | ||
Siemens Simatic Ipc227g Firmware | ||
Siemens Simatic Ipc227g | ||
Siemens Simatic Ipc277g Firmware | ||
Siemens Simatic Ipc277g | ||
Siemens Simatic Itp1000 Firmware | ||
Siemens Simatic Itp1000 | ||
Siemens Simatic Ipc477e Pro Firmware | ||
Siemens Simatic Ipc477e Pro | ||
Siemens Simatic Ipc627e Firmware | ||
Siemens Simatic Ipc627e | ||
Siemens Simatic Ipc647e Firmware | ||
Siemens Simatic Ipc647e | ||
Siemens Simatic Ipc677e Firmware | ||
Siemens Simatic Ipc677e | ||
Siemens Simatic Ipc847e Firmware | ||
Siemens Simatic Ipc847e | ||
Siemens Simatic Ipc327g Firmware | ||
Siemens Simatic Ipc327g | ||
Siemens Simatic Ipc377g Firmware | ||
Siemens Simatic Ipc377g | ||
Siemens Simatic Ipc427e Firmware | ||
Siemens Simatic Ipc427e | ||
Siemens Simatic Ipc477e Firmware | ||
Siemens Simatic Ipc477e | ||
Siemens Simatic Field Pg M5 Firmware | ||
Siemens Simatic Field Pg M5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2020-5953.
The affected software includes InsydeH2O UEFI Firmware versions 5.12.09.0074, 5.23.04.0045, 5.23.45.0023, 5.33.15.0034, 5.34.03.0029, and 5.42.03.0010.
The severity of CVE-2020-5953 is high, with a CVSS score of 7.5.
This vulnerability allows an attacker to execute arbitrary code in SMM (System Management Mode) by exploiting a vulnerability in the System Management Interrupt (SWSMI) handler of InsydeH2O UEFI Firmware.
Yes, it is recommended to update to the latest version of InsydeH2O UEFI Firmware to mitigate this vulnerability.