---
id: CVE-2020-27339
title: >-
  In the kernel in Insyde InsydeH2O 5.x, certain SMM drivers did not correctly
  validate the CommBuffer and CommBufferSize parameters, allowing callers to
  corrupt either the firmware or the OS memory
summary: >-
  In the kernel in Insyde InsydeH2O 5.x, certain SMM drivers did not correctly
  validate the CommBuffer and CommBufferSize parameters, allowing callers to
  corrupt either the firmware or the OS memory. The fixed versions for this
  issue in th…
severity: medium
cvss: 6.7
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-20
vendor: insyde
product: insydeh2o
affected:
  - 'insydeh2o >= 5.3, < 5.34.44'
  - 'insydeh2o >= 5.2, < 5.25.44'
  - 'insydeh2o >= 5.1, < 5.16.25'
  - 'insydeh2o >= 5.4, < 5.42.44'
  - 'insydeh2o >= 5.3, < 5.35.25'
  - 'insydeh2o >= 5.2, < 5.26.25'
  - 'insydeh2o >= 5.4, < 5.43.25'
  - ruggedcom_apr1808_firmware
  - simatic_field_pg_m5_firmware
  - simatic_field_pg_m6_firmware
  - simatic_ipc127e_firmware
  - simatic_ipc227g_firmware
  - simatic_ipc277g_firmware
  - simatic_ipc327g_firmware
  - simatic_ipc377g_firmware
  - simatic_ipc427e_firmware
  - simatic_ipc477e_firmware
  - simatic_ipc477e_pro_firmware
  - simatic_ipc627e_firmware
  - simatic_ipc647e_firmware
  - simatic_ipc677e_firmware
  - simatic_ipc847e_firmware
  - simatic_itp1000_firmware
patched:
  - insydeh2o 5.43.25
published: '2021-06-16'
updated: '2026-08-11'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-27339'
references:
  - url: 'https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf'
    label: cve@mitre.org
  - url: 'https://security.netapp.com/advisory/ntap-20220216-0005/'
    label: cve@mitre.org
  - url: 'https://www.insyde.com/security-pledge/SA-2021001'
    label: cve@mitre.org
  - url: 'https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20220216-0005/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.insyde.com/security-pledge/SA-2021001'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.kb.cert.org/vuls/id/796611'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-306654.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
tags:
  - nvd
epss: 0.00317
epssPercentile: 0.21895
ingestedAt: '2026-08-11T13:46:49.946Z'
---

## Overview

In the kernel in Insyde InsydeH2O 5.x, certain SMM drivers did not correctly validate the CommBuffer and CommBufferSize parameters, allowing callers to corrupt either the firmware or the OS memory. The fixed versions for this issue in the AhciBusDxe, IdeBusDxe, NvmExpressDxe, SdHostDriverDxe, and SdMmcDeviceDxe drivers are 05.16.25, 05.26.25, 05.35.25, 05.43.25, and 05.51.25 (for Kernel 5.1 through 5.5).

## Affected

- `insydeh2o >= 5.3, < 5.34.44`
- `insydeh2o >= 5.2, < 5.25.44`
- `insydeh2o >= 5.1, < 5.16.25`
- `insydeh2o >= 5.4, < 5.42.44`
- `insydeh2o >= 5.3, < 5.35.25`
- `insydeh2o >= 5.2, < 5.26.25`
- `insydeh2o >= 5.4, < 5.43.25`
- `ruggedcom_apr1808_firmware`
- `simatic_field_pg_m5_firmware`
- `simatic_field_pg_m6_firmware`
- `simatic_ipc127e_firmware`
- `simatic_ipc227g_firmware`
- `simatic_ipc277g_firmware`
- `simatic_ipc327g_firmware`
- `simatic_ipc377g_firmware`
- `simatic_ipc427e_firmware`
- `simatic_ipc477e_firmware`
- `simatic_ipc477e_pro_firmware`
- `simatic_ipc627e_firmware`
- `simatic_ipc647e_firmware`
- `simatic_ipc677e_firmware`
- `simatic_ipc847e_firmware`
- `simatic_itp1000_firmware`

## Remediation

Upgrade past the affected range:

- `insydeh2o 5.43.25`
