An issue was discovered in Insyde InsydeH2O with Kernel 5.0 before 05.08.42, Kernel 5.1 before 05.16.42, Kernel 5.2 before 05.26.42, Kernel 5.3 before 05.35.42, Kernel 5.4 before 05.42.51, and Kernel 5.5 before 05.50.51. An SMM memory corruption vulnerability in FvbServicesRuntimeDxe allows a possible attacker to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM.
Se ha descubierto un problema en InsydeH2O con el Kernel versión 5.0 antes de 05.08.42, el Kernel 5.1 antes de 05.16.42, el Kernel versión 5.2 antes de 05.26.42, el Kernel versión 5.3 antes de 05.35.42, el Kernel versión 5.4 antes de 05.42.51 y el Kernel versión 5.5 antes de 05.50.51. Una vulnerabilidad de corrupción de memoria SMM en FvbServicesRuntimeDxe permite a un posible atacante escribir datos fijos o predecibles en la SMRAM. La explotación de este problema podría llevar a escalar privilegios a SMM.
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
| Attack Vector | LOCAL |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | HIGH |
| User Interaction | NONE |
| Scope | CHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | HIGH |
AV:L/AC:L/Au:N/C:C/I:C/A:C
| Access Vector | LOCAL |
|---|---|
| Access Complexity | LOW |
| Authentication | NONE |
| Confidentiality Impact | COMPLETE |
| Integrity Impact | COMPLETE |
| Availability Impact | COMPLETE |
| Source | Type | Description |
|---|---|---|
| [email protected] | Primary |
en
CWE-787
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| insyde | insydeh2o | * | <built-in method update of dict object at 0x72f0592d4cc0> | Application |
| insyde | insydeh2o | * | <built-in method update of dict object at 0x72f03af44780> | Application |
| insyde | insydeh2o | * | <built-in method update of dict object at 0x72f03a95c9c0> | Application |
| insyde | insydeh2o | * | <built-in method update of dict object at 0x72f03a95e2c0> | Application |
| insyde | insydeh2o | * | <built-in method update of dict object at 0x72f0592d7d80> | Application |
| insyde | insydeh2o | * | <built-in method update of dict object at 0x72f0592d4380> | Application |
| siemens | simatic_field_pg_m5_firmware | * | <built-in method update of dict object at 0x72f03a95fa80> | Operating System |
| siemens | simatic_field_pg_m6_firmware | * | <built-in method update of dict object at 0x72f03a95e700> | Operating System |
| siemens | simatic_ipc127e_firmware | * | <built-in method update of dict object at 0x72effeddca40> | Operating System |
| siemens | simatic_ipc227g_firmware | * | <built-in method update of dict object at 0x72f0592d7e40> | Operating System |
| siemens | simatic_ipc277g_firmware | * | <built-in method update of dict object at 0x72effee34e00> | Operating System |
| siemens | simatic_ipc327g_firmware | * | <built-in method update of dict object at 0x72effec6de40> | Operating System |
| siemens | simatic_ipc377g_firmware | * | <built-in method update of dict object at 0x72f03a95c440> | Operating System |
| siemens | simatic_ipc427e_firmware | * | <built-in method update of dict object at 0x72effec6ff40> | Operating System |
| siemens | simatic_ipc477e_firmware | * | <built-in method update of dict object at 0x72f08056f1c0> | Operating System |
| siemens | simatic_ipc627e_firmware | * | <built-in method update of dict object at 0x72f05a4ef180> | Operating System |
| siemens | simatic_ipc647e_firmware | * | <built-in method update of dict object at 0x72effec6c380> | Operating System |
| siemens | simatic_ipc677e_firmware | * | <built-in method update of dict object at 0x72f03a95d000> | Operating System |
| siemens | simatic_ipc847e_firmware | * | <built-in method update of dict object at 0x72f03a95e000> | Operating System |
| siemens | simatic_itp1000_firmware | * | <built-in method update of dict object at 0x72f05a6bb480> | Operating System |
| siemens | ruggedcom_ape1808_firmware | * | <built-in method update of dict object at 0x72f05a796000> | Operating System |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:insyde:insydeh2o:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:insyde:insydeh2o:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:insyde:insydeh2o:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:insyde:insydeh2o:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:insyde:insydeh2o:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:insyde:insydeh2o:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:simatic_field_pg_m5_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:simatic_field_pg_m5:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:simatic_field_pg_m6_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:simatic_field_pg_m6:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:simatic_ipc127e_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:simatic_ipc127e:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:simatic_ipc227g_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:simatic_ipc227g:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:simatic_ipc277g_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:simatic_ipc277g:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:simatic_ipc327g_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:simatic_ipc327g:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:simatic_ipc377g_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:simatic_ipc377g:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:simatic_ipc427e_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:simatic_ipc427e:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:simatic_ipc477e_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:simatic_ipc477e:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:simatic_ipc627e_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:simatic_ipc627e:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:simatic_ipc647e_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:simatic_ipc647e:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:simatic_ipc677e_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:simatic_ipc677e:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:simatic_ipc847e_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:simatic_ipc847e:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:simatic_itp1000_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:simatic_itp1000:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:ruggedcom_ape1808_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:ruggedcom_ape1808:-:*:*:*:*:*:*:* |