An issue was discovered in Insyde InsydeH2O Kernel 5.0 before 05.09.11, 5.1 before 05.17.11, 5.2 before 05.27.11, 5.3 before 05.36.11, 5.4 before 05.44.11, and 5.5 before 05.52.11 affecting FwBlockServiceSmm. Software SMI services that use the Communicate() function of the EFI_SMM_COMMUNICATION_PROTOCOL do not check whether the address of the buffer is valid, which allows use of SMRAM, MMIO, or OS kernel addresses.
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HInsyde Insydeh2o
APPInsyde5.1 – 5.16.29 (excl.)5.2 – 5.26.29 (excl.)5.3 – 5.35.29 (excl.)5.0 – 5.08.29 (excl.)Siemens Simatic Field Pg M5
HWSiemensall versionsSiemens Simatic Field Pg M5 Firmware
OSSiemensall versionsSiemens Simatic Field Pg M6
HWSiemensall versionsSiemens Simatic Field Pg M6 Firmware
OSSiemensall versionsSiemens Simatic Ipc127e
HWSiemensall versionsSiemens Simatic Ipc127e Firmware
OSSiemensall versionsSiemens Simatic Ipc227g
HWSiemensall versionsSiemens Simatic Ipc227g Firmware
OSSiemensall versionsSiemens Simatic Ipc277g
HWSiemensall versionsSiemens Simatic Ipc277g Firmware
OSSiemensall versionsSiemens Simatic Ipc327g
HWSiemensall versionsSiemens Simatic Ipc327g Firmware
OSSiemensall versionsSiemens Simatic Ipc377g
HWSiemensall versionsSiemens Simatic Ipc377g Firmware
OSSiemensall versionsSiemens Simatic Ipc427e
HWSiemensall versionsSiemens Simatic Ipc427e Firmware
OSSiemensall versionsSiemens Simatic Ipc477e
HWSiemensall versionsSiemens Simatic Ipc477e Firmware
OSSiemensall versionsSiemens Simatic Ipc627e
HWSiemensall versionsSiemens Simatic Ipc627e Firmware
OSSiemensall versionsSiemens Simatic Ipc647e
HWSiemensall versionsSiemens Simatic Ipc647e Firmware
OSSiemensall versionsSiemens Simatic Ipc677e
HWSiemensall versionsSiemens Simatic Ipc677e Firmware
OSSiemensall versionsSiemens Simatic Ipc847e
HWSiemensall versionsSiemens Simatic Ipc847e Firmware
OSSiemensall versionsSiemens Simatic Itp1000
HWSiemensall versionsSiemens Simatic Itp1000 Firmware
OSSiemensall versions
Related vulnerabilities
Privilege Escalation w Intel AMT/ISM/SBT — nieautoryzowany dostęp systemowy
Nieautoryzowany dostęp w maxView Storage Manager via Redfish Server
Stack buffer overflow w AsfSecureBootDxe (InsydeH2O) — RCE w fazie DXE
RCE w Insyde InsydeH2O — brak weryfikacji CommBuffer w SMI handler
Improper input validation was discovered in UsbCoreDxe in Insyde InsydeH2O kernel 5.4 before 05.47.01, 5.5 bef...