SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-33625

Software SMI services that use the Communicate() function of the EFI_SMM_COMMUNICATION_PROTOCOL do not check whether the address of the buffer is valid, which allows use of SMRAM, MMIO, or OS kernel addresses.

HIGH 7.5EPSS 0.32%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.32%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

An issue was discovered in Kernel 5.x in Insyde InsydeH2O, affecting HddPassword. Software SMI services that use the Communicate() function of the EFI_SMM_COMMUNICATION_PROTOCOL do not check whether the address of the buffer is valid, which allows use of SMRAM, MMIO, or OS kernel addresses.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
EPSS
0.32% probability · 24th percentile
CISA KEV
Not listed
Weakness
CWE-119
Affected
insyde/insydeh2o · netapp/fas\/aff bios · siemens/ruggedcom ape1808 firmware · siemens/simatic field pg m5 firmware · siemens/simatic ipc127e firmware · siemens/simatic itp1000 firmware · siemens/simatic ipc277g firmware · siemens/simatic ipc227g firmware · siemens/simatic ipc327g firmware · siemens/simatic ipc377g firmware · siemens/simatic ipc427e firmware · siemens/simatic ipc477e firmware · siemens/simatic ipc477e pro firmware · siemens/simatic ipc627e firmware · siemens/simatic ipc647e firmware · siemens/simatic ipc677e firmware · siemens/simatic ipc847e firmware · siemens/simatic field pg m6 firmware
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.