CVE-2021-43615: High severity Insyde InsydeH2O vulnerability
An issue was discovered in HddPassword in Insyde InsydeH2O with kernel 5.1 before 05.16.23, 5.2 before 05.26.23, 5.3 before 05.35.23, 5.4 before 05.43.22, and 5.5 before 05.51.22. An SMM memory corruption vulnerability allows an attacker to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Insyde H2O (HddPassword)to a version that resolves this vulnerability.Fixed in 05.16.23 - Upgrade
Upgrade
Insyde H2O (HddPassword)to a version that resolves this vulnerability.Fixed in 05.26.23 - Upgrade
Upgrade
Insyde H2O (HddPassword)to a version that resolves this vulnerability.Fixed in 05.35.23 - Upgrade
Upgrade
Insyde H2O (HddPassword)to a version that resolves this vulnerability.Fixed in 05.43.22 - Upgrade
Upgrade
Insyde H2O (HddPassword)to a version that resolves this vulnerability.Fixed in 05.51.22
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-43615.
What is the severity of CVE-2021-43615?
The severity of CVE-2021-43615 is high (8.2).
Which software versions are affected by CVE-2021-43615?
The affected software versions are Insyde InsydeH2O with kernel 5.1 before 05.16.23, 5.2 before 05.26.23, 5.3 before 05.35.23, 5.4 before 05.43.22, and 5.5 before 05.51.22.
What is the vulnerability type of CVE-2021-43615?
CVE-2021-43615 is a memory corruption vulnerability.
Is there a fix available for CVE-2021-43615?
Please refer to the vendor's security advisories for information on available fixes.