First published: Thu Feb 03 2022(Updated: )
An issue was discovered in Kernel 5.x in Insyde InsydeH2O, affecting HddPassword. Software SMI services that use the Communicate() function of the EFI_SMM_COMMUNICATION_PROTOCOL do not check whether the address of the buffer is valid, which allows use of SMRAM, MMIO, or OS kernel addresses.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Insyde InsydeH2O | >=5.1<5.16.23 | |
Insyde InsydeH2O | >=5.2<5.26.23 | |
Insyde InsydeH2O | >=5.3<5.35.23 | |
Insyde InsydeH2O | >=5.4<5.43.22 | |
Insyde InsydeH2O | >=5.5<5.51.22 | |
Netapp Fas\/aff Bios | ||
Siemens Ruggedcom Ape1808 Firmware | ||
Siemens Ruggedcom Ape1808 | ||
Siemens Simatic Field Pg M5 Firmware | ||
Siemens Simatic Field Pg M5 | ||
Siemens Simatic Ipc127e Firmware | ||
Siemens Simatic Ipc127e | ||
Siemens Simatic Itp1000 Firmware | ||
Siemens Simatic Itp1000 | ||
Siemens Simatic Ipc277g Firmware | ||
Siemens Simatic Ipc277g | ||
Siemens Simatic Ipc227g Firmware | ||
Siemens Simatic Ipc227g | ||
Siemens Simatic Ipc327g Firmware | ||
Siemens Simatic Ipc327g | ||
Siemens Simatic Ipc377g Firmware | ||
Siemens Simatic Ipc377g | ||
Siemens Simatic Ipc427e Firmware | ||
Siemens Simatic Ipc427e | ||
Siemens Simatic Ipc477e Firmware | ||
Siemens Simatic Ipc477e | ||
Siemens Simatic Ipc477e Pro Firmware | ||
Siemens Simatic Ipc477e Pro | ||
Siemens Simatic Ipc627e Firmware | ||
Siemens Simatic Ipc627e | ||
Siemens Simatic Ipc647e Firmware | ||
Siemens Simatic Ipc647e | ||
Siemens Simatic Ipc677e Firmware | ||
Siemens Simatic Ipc677e | ||
Siemens Simatic Ipc847e Firmware | ||
Siemens Simatic Ipc847e | ||
Siemens Simatic Field Pg M6 Firmware | ||
Siemens Simatic Field Pg M6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-33625 is an issue in Kernel 5.x in Insyde InsydeH2O that affects HddPassword and allows the use of SMRAM, MMIO, or OS kernel addresses.
CVE-2021-33625 affects versions 5.1 to 5.51.22 of Insyde InsydeH2O.
CVE-2021-33625 has a severity score of 7.5 (High).
To fix CVE-2021-33625, update Insyde InsydeH2O to a version beyond 5.51.22.
You can find more information about CVE-2021-33625 in the following references: [Siemens CERT-SSA-306654](https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf), [Netapp Advisory NTAP-20220222-0004](https://security.netapp.com/advisory/ntap-20220222-0004/), [Insyde Security Pledge](https://www.insyde.com/security-pledge).