CVE-2020-5953

A vulnerability exists in System Management Interrupt (SWSMI) handler of InsydeH2O UEFI Firmware code located in SWSMI handler that dereferences gRT (EFI_RUNTIME_SERVICES) pointer to call a GetVariable service, which is located outside of SMRAM. This can result in code execution in SMM (escalating privilege from ring 0 to ring -2).
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:insyde:insydeh2o:5.12.09.0074:*:*:*:*:*:*:*
cpe:2.3:a:insyde:insydeh2o:5.23.04.0045:*:*:*:*:*:*:*
cpe:2.3:a:insyde:insydeh2o:5.23.45.0023:*:*:*:*:*:*:*
cpe:2.3:a:insyde:insydeh2o:5.33.15.0034:*:*:*:*:*:*:*
cpe:2.3:a:insyde:insydeh2o:5.34.03.0029:*:*:*:*:*:*:*
cpe:2.3:a:insyde:insydeh2o:5.42.03.0010:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:siemens:ruggedcom_ape1808_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:ruggedcom_ape1808:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:siemens:simatic_field_pg_m6_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_field_pg_m6:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc127e_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc127e:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc227g_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc227g:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc277g_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc277g:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:siemens:simatic_itp1000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_itp1000:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc477e_pro_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc477e_pro:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc627e_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc627e:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc647e_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc647e:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc677e_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc677e:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc847e_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc847e:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc327g_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc327g:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc377g_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc377g:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc427e_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc427e:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc477e_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc477e:-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
cpe:2.3:o:siemens:simatic_field_pg_m5_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_field_pg_m5:-:*:*:*:*:*:*:*

History

12 Apr 2022, 18:17

Type Values Removed Values Added
References (CONFIRM) https://security.netapp.com/advisory/ntap-20220222-0005/ - (CONFIRM) https://security.netapp.com/advisory/ntap-20220222-0005/ - Third Party Advisory
References (CONFIRM) https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf - (CONFIRM) https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf - Third Party Advisory
CPE cpe:2.3:h:siemens:simatic_ipc477e_pro:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_field_pg_m6_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_ipc127e_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_ipc227g_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_field_pg_m6:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc127e:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_itp1000:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_ipc847e_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc677e:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_ipc677e_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc477e:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:ruggedcom_ape1808_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_ipc477e_pro_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_ipc327g_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc427e:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_field_pg_m5_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_ipc627e_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc627e:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_ipc377g_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc847e:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_ipc427e_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_ipc277g_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_ipc477e_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_itp1000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:ruggedcom_ape1808:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc647e:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc227g:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc327g:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc377g:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc277g:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_field_pg_m5:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_ipc647e_firmware:-:*:*:*:*:*:*:*

24 Feb 2022, 15:15

Type Values Removed Values Added
References
  • (CONFIRM) https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf -
  • (CONFIRM) https://security.netapp.com/advisory/ntap-20220222-0005/ -

09 Feb 2022, 20:00

Type Values Removed Values Added
CPE cpe:2.3:a:insyde:insydeh2o:5.34.03.0029:*:*:*:*:*:*:*
cpe:2.3:a:insyde:insydeh2o:5.42.03.0010:*:*:*:*:*:*:*
cpe:2.3:a:insyde:insydeh2o:5.23.04.0045:*:*:*:*:*:*:*
cpe:2.3:a:insyde:insydeh2o:5.33.15.0034:*:*:*:*:*:*:*
cpe:2.3:a:insyde:insydeh2o:5.23.45.0023:*:*:*:*:*:*:*
cpe:2.3:a:insyde:insydeh2o:5.12.09.0074:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 6.9
v3 : 7.5
References (MISC) https://www.insyde.com/products - (MISC) https://www.insyde.com/products - Product, Vendor Advisory
References (MISC) https://www.insyde.com/security-pledge - (MISC) https://www.insyde.com/security-pledge - Vendor Advisory
CWE NVD-CWE-noinfo

03 Feb 2022, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-02-03 01:15

Updated : 2024-02-04 22:08


NVD link : CVE-2020-5953

Mitre link : CVE-2020-5953

CVE.ORG link : CVE-2020-5953


JSON object : View

Products Affected

siemens

  • ruggedcom_ape1808_firmware
  • simatic_ipc227g
  • simatic_field_pg_m6_firmware
  • simatic_ipc647e_firmware
  • simatic_ipc477e_pro_firmware
  • simatic_ipc227g_firmware
  • simatic_ipc327g_firmware
  • simatic_ipc847e
  • simatic_ipc377g_firmware
  • simatic_itp1000
  • simatic_ipc477e_pro
  • simatic_ipc377g
  • simatic_ipc477e
  • simatic_ipc647e
  • simatic_ipc277g
  • ruggedcom_ape1808
  • simatic_ipc327g
  • simatic_ipc627e
  • simatic_ipc847e_firmware
  • simatic_field_pg_m5_firmware
  • simatic_ipc427e
  • simatic_itp1000_firmware
  • simatic_ipc627e_firmware
  • simatic_ipc127e_firmware
  • simatic_field_pg_m5
  • simatic_field_pg_m6
  • simatic_ipc427e_firmware
  • simatic_ipc477e_firmware
  • simatic_ipc677e_firmware
  • simatic_ipc677e
  • simatic_ipc127e
  • simatic_ipc277g_firmware

insyde

  • insydeh2o