A vulnerability exists in System Management Interrupt (SWSMI) handler of InsydeH2O UEFI Firmware code located in SWSMI handler that dereferences gRT (EFI_RUNTIME_SERVICES) pointer to call a GetVariable service, which is located outside of SMRAM. This can result in code execution in SMM (escalating privilege from ring 0 to ring -2).
References
Link | Resource |
---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf | Third Party Advisory |
https://security.netapp.com/advisory/ntap-20220222-0005/ | Third Party Advisory |
https://www.insyde.com/products | Product Vendor Advisory |
https://www.insyde.com/security-pledge | Vendor Advisory |
https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf | Third Party Advisory |
https://security.netapp.com/advisory/ntap-20220222-0005/ | Third Party Advisory |
https://www.insyde.com/products | Product Vendor Advisory |
https://www.insyde.com/security-pledge | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
Configuration 9 (hide)
AND |
|
Configuration 10 (hide)
AND |
|
Configuration 11 (hide)
AND |
|
Configuration 12 (hide)
AND |
|
Configuration 13 (hide)
AND |
|
Configuration 14 (hide)
AND |
|
Configuration 15 (hide)
AND |
|
Configuration 16 (hide)
AND |
|
Configuration 17 (hide)
AND |
|
History
21 Nov 2024, 05:34
Type | Values Removed | Values Added |
---|---|---|
References | () https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf - Third Party Advisory | |
References | () https://security.netapp.com/advisory/ntap-20220222-0005/ - Third Party Advisory | |
References | () https://www.insyde.com/products - Product, Vendor Advisory | |
References | () https://www.insyde.com/security-pledge - Vendor Advisory |
12 Apr 2022, 18:17
Type | Values Removed | Values Added |
---|---|---|
References | (CONFIRM) https://security.netapp.com/advisory/ntap-20220222-0005/ - Third Party Advisory | |
References | (CONFIRM) https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf - Third Party Advisory | |
CPE | cpe:2.3:h:siemens:simatic_ipc477e_pro:-:*:*:*:*:*:*:* cpe:2.3:o:siemens:simatic_field_pg_m6_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:siemens:simatic_ipc127e_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:siemens:simatic_ipc227g_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:siemens:simatic_field_pg_m6:-:*:*:*:*:*:*:* cpe:2.3:h:siemens:simatic_ipc127e:-:*:*:*:*:*:*:* cpe:2.3:h:siemens:simatic_itp1000:-:*:*:*:*:*:*:* cpe:2.3:o:siemens:simatic_ipc847e_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:siemens:simatic_ipc677e:-:*:*:*:*:*:*:* cpe:2.3:o:siemens:simatic_ipc677e_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:siemens:simatic_ipc477e:-:*:*:*:*:*:*:* cpe:2.3:o:siemens:ruggedcom_ape1808_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:siemens:simatic_ipc477e_pro_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:siemens:simatic_ipc327g_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:siemens:simatic_ipc427e:-:*:*:*:*:*:*:* cpe:2.3:o:siemens:simatic_field_pg_m5_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:siemens:simatic_ipc627e_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:siemens:simatic_ipc627e:-:*:*:*:*:*:*:* cpe:2.3:o:siemens:simatic_ipc377g_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:siemens:simatic_ipc847e:-:*:*:*:*:*:*:* cpe:2.3:o:siemens:simatic_ipc427e_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:siemens:simatic_ipc277g_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:siemens:simatic_ipc477e_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:siemens:simatic_itp1000_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:siemens:ruggedcom_ape1808:-:*:*:*:*:*:*:* cpe:2.3:h:siemens:simatic_ipc647e:-:*:*:*:*:*:*:* cpe:2.3:h:siemens:simatic_ipc227g:-:*:*:*:*:*:*:* cpe:2.3:h:siemens:simatic_ipc327g:-:*:*:*:*:*:*:* cpe:2.3:h:siemens:simatic_ipc377g:-:*:*:*:*:*:*:* cpe:2.3:h:siemens:simatic_ipc277g:-:*:*:*:*:*:*:* cpe:2.3:h:siemens:simatic_field_pg_m5:-:*:*:*:*:*:*:* cpe:2.3:o:siemens:simatic_ipc647e_firmware:-:*:*:*:*:*:*:* |
24 Feb 2022, 15:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
09 Feb 2022, 20:00
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:insyde:insydeh2o:5.34.03.0029:*:*:*:*:*:*:* cpe:2.3:a:insyde:insydeh2o:5.42.03.0010:*:*:*:*:*:*:* cpe:2.3:a:insyde:insydeh2o:5.23.04.0045:*:*:*:*:*:*:* cpe:2.3:a:insyde:insydeh2o:5.33.15.0034:*:*:*:*:*:*:* cpe:2.3:a:insyde:insydeh2o:5.23.45.0023:*:*:*:*:*:*:* cpe:2.3:a:insyde:insydeh2o:5.12.09.0074:*:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : 6.9
v3 : 7.5 |
References | (MISC) https://www.insyde.com/products - Product, Vendor Advisory | |
References | (MISC) https://www.insyde.com/security-pledge - Vendor Advisory | |
CWE | NVD-CWE-noinfo |
03 Feb 2022, 01:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-02-03 01:15
Updated : 2024-11-21 05:34
NVD link : CVE-2020-5953
Mitre link : CVE-2020-5953
CVE.ORG link : CVE-2020-5953
JSON object : View
Products Affected
siemens
- simatic_ipc477e_pro
- simatic_ipc677e
- simatic_ipc127e_firmware
- simatic_ipc427e_firmware
- simatic_ipc427e
- simatic_itp1000
- simatic_ipc647e
- ruggedcom_ape1808_firmware
- ruggedcom_ape1808
- simatic_ipc627e_firmware
- simatic_ipc477e_firmware
- simatic_ipc647e_firmware
- simatic_ipc847e_firmware
- simatic_field_pg_m5
- simatic_field_pg_m6_firmware
- simatic_ipc227g
- simatic_ipc627e
- simatic_ipc477e_pro_firmware
- simatic_itp1000_firmware
- simatic_field_pg_m5_firmware
- simatic_ipc277g
- simatic_ipc327g
- simatic_ipc127e
- simatic_ipc277g_firmware
- simatic_ipc847e
- simatic_field_pg_m6
- simatic_ipc377g_firmware
- simatic_ipc677e_firmware
- simatic_ipc377g
- simatic_ipc227g_firmware
- simatic_ipc477e
- simatic_ipc327g_firmware
insyde
- insydeh2o
CWE