First published: Thu Feb 03 2022(Updated: )
An issue was discovered in Kernel 5.x in Insyde InsydeH2O, affecting HddPassword. Software SMI services that use the Communicate() function of the EFI_SMM_COMMUNICATION_PROTOCOL do not check whether the address of the buffer is valid, which allows use of SMRAM, MMIO, or OS kernel addresses.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Insyde InsydeH2O UEFI BIOS | >=5.1<5.16.23 | |
Insyde InsydeH2O UEFI BIOS | >=5.2<5.26.23 | |
Insyde InsydeH2O UEFI BIOS | >=5.3<5.35.23 | |
Insyde InsydeH2O UEFI BIOS | >=5.4<5.43.22 | |
Insyde InsydeH2O UEFI BIOS | >=5.5<5.51.22 | |
NetApp FAS/AFF BIOS | ||
Siemens Ruggedcom APE1808 | ||
Siemens Ruggedcom APE1808 Firmware | ||
Siemens Simatic Field PG M5 | ||
Siemens Simatic Field PG M5 | ||
siemens simatic ipc127e firmware | ||
siemens simatic ipc127e | ||
Siemens Simatic ITP1000 | ||
Siemens Simatic ITP1000 Firmware | ||
Siemens Simatic IPC277G | ||
Siemens Simatic IPC277G | ||
Siemens Simatic IPC227G | ||
Siemens Simatic IPC227G Firmware | ||
Siemens Simatic IPC327G Firmware | ||
Siemens Simatic IPC327G Firmware | ||
Siemens Simatic IPC377G | ||
Siemens Simatic IPC377G | ||
Siemens Simatic IPC427E Firmware | ||
Siemens Simatic IPC427E Firmware | ||
Siemens Simatic IPC477E Firmware | ||
Siemens Simatic IPC477E Firmware | ||
Siemens Simatic IPC477E Pro | ||
Siemens Simatic IPC477E Firmware | ||
siemens simatic ipc627e firmware | ||
siemens simatic ipc627e | ||
siemens simatic ipc647e firmware | ||
siemens simatic ipc647e | ||
siemens simatic ipc677e firmware | ||
siemens simatic ipc677e | ||
siemens simatic ipc847e firmware | ||
siemens simatic ipc847e | ||
siemens simatic field pg m6 firmware | ||
siemens simatic field pg m6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-33625 is an issue in Kernel 5.x in Insyde InsydeH2O that affects HddPassword and allows the use of SMRAM, MMIO, or OS kernel addresses.
CVE-2021-33625 affects versions 5.1 to 5.51.22 of Insyde InsydeH2O.
CVE-2021-33625 has a severity score of 7.5 (High).
To fix CVE-2021-33625, update Insyde InsydeH2O to a version beyond 5.51.22.
You can find more information about CVE-2021-33625 in the following references: [Siemens CERT-SSA-306654](https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf), [Netapp Advisory NTAP-20220222-0004](https://security.netapp.com/advisory/ntap-20220222-0004/), [Insyde Security Pledge](https://www.insyde.com/security-pledge).