CVE-2021-33626: High severity Insyde InsydeH2O vulnerability
A vulnerability exists in SMM (System Management Mode) branch that registers a SWSMI handler that does not sufficiently check or validate the allocated buffer pointer(QWORD values for CommBuffer). This can be used by an attacker to corrupt data in SMRAM memory and even lead to arbitrary code execution.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-33626?
CVE-2021-33626 is a vulnerability that exists in the SMM (System Management Mode) branch, allowing an attacker to corrupt data in SMRAM memory and execute arbitrary code.
Which software is affected by CVE-2021-33626?
Insyde InsydeH2O versions 5.3 to 5.34.44, 5.2 to 5.25.44, 5.1 to 5.16.25, 5.4 to 5.42.44, 5.3 to 5.35.25, 5.2 to 5.26.25, 5.4 to 5.43.25, Siemens Ruggedcom Apr1808 Firmware
What is the severity of CVE-2021-33626?
The severity of CVE-2021-33626 is high (7.8).
How can I fix CVE-2021-33626?
Apply the recommended security patches provided by the software vendors or follow the mitigation steps outlined in the advisories.
Where can I find more information about CVE-2021-33626?
You can find more information about CVE-2021-33626 in the provided references: [1] [2] [3]