First published: Thu Feb 03 2022(Updated: )
An issue was discovered in Insyde InsydeH2O with Kernel 5.0 before 05.08.42, Kernel 5.1 before 05.16.42, Kernel 5.2 before 05.26.42, Kernel 5.3 before 05.35.42, Kernel 5.4 before 05.42.51, and Kernel 5.5 before 05.50.51. An SMM memory corruption vulnerability in FvbServicesRuntimeDxe allows a possible attacker to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Insyde InsydeH2O | >=5.0<5.08.42 | |
Insyde InsydeH2O | >=5.1<5.16.42 | |
Insyde InsydeH2O | >=5.2<5.26.42 | |
Insyde InsydeH2O | >=5.3<5.35.42 | |
Insyde InsydeH2O | >=5.4<5.42.51 | |
Insyde InsydeH2O | >=5.5<5.50.51 | |
Siemens Simatic Field Pg M5 Firmware | ||
Siemens Simatic Field Pg M5 | ||
Siemens Simatic Field Pg M6 Firmware | ||
Siemens Simatic Field Pg M6 | ||
Siemens Simatic Ipc127e Firmware | ||
Siemens Simatic Ipc127e | ||
Siemens Simatic Ipc227g Firmware | ||
Siemens Simatic Ipc227g | ||
Siemens Simatic Ipc277g Firmware | ||
Siemens Simatic Ipc277g | ||
Siemens Simatic Ipc327g Firmware | ||
Siemens Simatic Ipc327g | ||
Siemens Simatic Ipc377g Firmware | ||
Siemens Simatic Ipc377g | ||
Siemens Simatic Ipc427e Firmware | ||
Siemens Simatic Ipc427e | ||
Siemens Simatic Ipc477e Firmware | ||
Siemens Simatic Ipc477e | ||
Siemens Simatic Ipc627e Firmware | ||
Siemens Simatic Ipc627e | ||
Siemens Simatic Ipc647e Firmware | ||
Siemens Simatic Ipc647e | ||
Siemens Simatic Ipc677e Firmware | ||
Siemens Simatic Ipc677e | ||
Siemens Simatic Ipc847e Firmware | ||
Siemens Simatic Ipc847e | ||
Siemens Simatic Itp1000 Firmware | ||
Siemens Simatic Itp1000 | ||
Siemens Ruggedcom Ape1808 Firmware | ||
Siemens Ruggedcom Ape1808 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-42554 is a vulnerability discovered in Insyde InsydeH2O with Kernel 5.0 before 05.08.42, Kernel 5.1 before 05.16.42, Kernel 5.2 before 05.26.42, Kernel 5.3 before 05.35.42, Kernel 5.4 before 05.42.51, and Kernel 5.5 before 05.50.51. It is an SMM memory corruption vulnerability in FvbServicesRuntimeDxe.
CVE-2021-42554 has a severity rating of 8.2, which is considered high.
Insyde InsydeH2O versions 5.0 to 5.5 are affected by CVE-2021-42554.
To fix CVE-2021-42554, it is recommended to update Insyde InsydeH2O to a version above 05.50.51, if available.
You can find more information about CVE-2021-42554 in the following references: [1] [2] [3]