An issue was discovered in Insyde InsydeH2O Kernel 5.0 before 05.09.11, 5.1 before 05.17.11, 5.2 before 05.27.11, 5.3 before 05.36.11, 5.4 before 05.44.11, and 5.5 before 05.52.11 affecting FwBlockServiceSmm. Software SMI services that use the Communicate() function of the EFI_SMM_COMMUNICATION_PROTOCOL do not check whether the address of the buffer is valid, which allows use of SMRAM, MMIO, or OS kernel addresses.
Se ha descubierto un problema en InsydeH2O versión 5.x, que afecta a FwBlockServiceSmm. Los servicios SMI de software que utilizan la función Communicate() del EFI_SMM_COMMUNICATION_PROTOCOL no comprueban si la dirección del búfer es válida, lo que permite el uso de direcciones SMRAM, MMIO o del núcleo del SO
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
| Attack Vector | LOCAL |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | HIGH |
| User Interaction | NONE |
| Scope | CHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | HIGH |
AV:L/AC:L/Au:N/C:C/I:C/A:C
| Access Vector | LOCAL |
|---|---|
| Access Complexity | LOW |
| Authentication | NONE |
| Confidentiality Impact | COMPLETE |
| Integrity Impact | COMPLETE |
| Availability Impact | COMPLETE |
| Source | Type | Description |
|---|---|---|
| [email protected] | Primary |
en
CWE-119
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| insyde | insydeh2o | * | <built-in method update of dict object at 0x72f05a3a6240> | Application |
| insyde | insydeh2o | * | <built-in method update of dict object at 0x72f05a795400> | Application |
| insyde | insydeh2o | * | <built-in method update of dict object at 0x72f05a4efd00> | Application |
| insyde | insydeh2o | * | <built-in method update of dict object at 0x72efbccaed00> | Application |
| siemens | simatic_field_pg_m5_firmware | * | <built-in method update of dict object at 0x72f0592d4380> | Operating System |
| siemens | simatic_field_pg_m6_firmware | * | <built-in method update of dict object at 0x72f0592d7e40> | Operating System |
| siemens | simatic_ipc127e_firmware | * | <built-in method update of dict object at 0x72f05a4edc80> | Operating System |
| siemens | simatic_ipc227g_firmware | * | <built-in method update of dict object at 0x72f03af46300> | Operating System |
| siemens | simatic_ipc277g_firmware | * | <built-in method update of dict object at 0x72f08056c040> | Operating System |
| siemens | simatic_ipc327g_firmware | * | <built-in method update of dict object at 0x72f0592d6940> | Operating System |
| siemens | simatic_ipc377g_firmware | * | <built-in method update of dict object at 0x72f05a3a4840> | Operating System |
| siemens | simatic_ipc427e_firmware | * | <built-in method update of dict object at 0x72effec6e040> | Operating System |
| siemens | simatic_ipc477e_firmware | * | <built-in method update of dict object at 0x72f0805a5fc0> | Operating System |
| siemens | simatic_ipc627e_firmware | * | <built-in method update of dict object at 0x72f05a795780> | Operating System |
| siemens | simatic_ipc647e_firmware | * | <built-in method update of dict object at 0x72f03af446c0> | Operating System |
| siemens | simatic_ipc677e_firmware | * | <built-in method update of dict object at 0x72effedcc4c0> | Operating System |
| siemens | simatic_ipc847e_firmware | * | <built-in method update of dict object at 0x72f03af47600> | Operating System |
| siemens | simatic_itp1000_firmware | * | <built-in method update of dict object at 0x72f05a3a7180> | Operating System |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:insyde:insydeh2o:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:insyde:insydeh2o:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:insyde:insydeh2o:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:insyde:insydeh2o:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:simatic_field_pg_m5_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:simatic_field_pg_m5:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:simatic_field_pg_m6_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:simatic_field_pg_m6:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:simatic_ipc127e_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:simatic_ipc127e:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:simatic_ipc227g_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:simatic_ipc227g:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:simatic_ipc277g_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:simatic_ipc277g:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:simatic_ipc327g_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:simatic_ipc327g:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:simatic_ipc377g_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:simatic_ipc377g:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:simatic_ipc427e_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:simatic_ipc427e:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:simatic_ipc477e_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:simatic_ipc477e:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:simatic_ipc627e_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:simatic_ipc627e:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:simatic_ipc647e_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:simatic_ipc647e:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:simatic_ipc677e_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:simatic_ipc677e:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:simatic_ipc847e_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:simatic_ipc847e:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:simatic_itp1000_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:simatic_itp1000:-:*:*:*:*:*:*:* |