CVE-2021-33625: Buffer Overflow
An issue was discovered in Kernel 5.x in Insyde InsydeH2O, affecting HddPassword. Software SMI services that use the Communicate() function of the EFISMMCOMMUNICATIONPROTOCOL do not check whether the address of the buffer is valid, which allows use of SMRAM, MMIO, or OS kernel addresses.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-33625?
CVE-2021-33625 is an issue in Kernel 5.x in Insyde InsydeH2O that affects HddPassword and allows the use of SMRAM, MMIO, or OS kernel addresses.
What software versions are affected by CVE-2021-33625?
CVE-2021-33625 affects versions 5.1 to 5.51.22 of Insyde InsydeH2O.
What is the severity of CVE-2021-33625?
CVE-2021-33625 has a severity score of 7.5 (High).
How can I fix CVE-2021-33625?
To fix CVE-2021-33625, update Insyde InsydeH2O to a version beyond 5.51.22.
Where can I find more information about CVE-2021-33625?
You can find more information about CVE-2021-33625 in the following references: [Siemens CERT-SSA-306654](https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf), [Netapp Advisory NTAP-20220222-0004](https://security.netapp.com/advisory/ntap-20220222-0004/), [Insyde Security Pledge](https://www.insyde.com/security-pledge).