---
id: CVE-2020-5953
title: >-
  A vulnerability exists in System Management Interrupt (SWSMI) handler of
  InsydeH2O UEFI Firmware code located in SWSMI handler that dereferences gRT
  (EFI_RUNTIME_SERVICES) pointer to call a GetVariable service, which is located
  outside o…
summary: >-
  A vulnerability exists in System Management Interrupt (SWSMI) handler of
  InsydeH2O UEFI Firmware code located in SWSMI handler that dereferences gRT
  (EFI_RUNTIME_SERVICES) pointer to call a GetVariable service, which is located
  outside o…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'
vendor: insyde
product: insydeh2o
affected:
  - insydeh2o = 5.12.09.0074
  - insydeh2o = 5.23.04.0045
  - insydeh2o = 5.23.45.0023
  - insydeh2o = 5.33.15.0034
  - insydeh2o = 5.34.03.0029
  - insydeh2o = 5.42.03.0010
  - ruggedcom_ape1808_firmware
  - simatic_field_pg_m6_firmware
  - simatic_ipc127e_firmware
  - simatic_ipc227g_firmware
  - simatic_ipc277g_firmware
  - simatic_itp1000_firmware
  - simatic_ipc477e_pro_firmware
  - simatic_ipc627e_firmware
  - simatic_ipc647e_firmware
  - simatic_ipc677e_firmware
  - simatic_ipc847e_firmware
  - simatic_ipc327g_firmware
  - simatic_ipc377g_firmware
  - simatic_ipc427e_firmware
  - simatic_ipc477e_firmware
  - simatic_field_pg_m5_firmware
published: '2022-02-03'
updated: '2026-08-11'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-5953'
references:
  - url: 'https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf'
    label: cve@mitre.org
  - url: 'https://security.netapp.com/advisory/ntap-20220222-0005/'
    label: cve@mitre.org
  - url: 'https://www.insyde.com/products'
    label: cve@mitre.org
  - url: 'https://www.insyde.com/security-pledge'
    label: cve@mitre.org
  - url: 'https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20220222-0005/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.insyde.com/products'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.insyde.com/security-pledge'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.kb.cert.org/vuls/id/796611'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-306654.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
tags:
  - nvd
epss: 0.00284
epssPercentile: 0.21156
ingestedAt: '2026-08-11T16:47:01.700Z'
---

## Overview

A vulnerability exists in System Management Interrupt (SWSMI) handler of InsydeH2O UEFI Firmware code located in SWSMI handler that dereferences gRT (EFI_RUNTIME_SERVICES) pointer to call a GetVariable service, which is located outside of SMRAM. This can result in code execution in SMM (escalating privilege from ring 0 to ring -2).

## Affected

- `insydeh2o = 5.12.09.0074`
- `insydeh2o = 5.23.04.0045`
- `insydeh2o = 5.23.45.0023`
- `insydeh2o = 5.33.15.0034`
- `insydeh2o = 5.34.03.0029`
- `insydeh2o = 5.42.03.0010`
- `ruggedcom_ape1808_firmware`
- `simatic_field_pg_m6_firmware`
- `simatic_ipc127e_firmware`
- `simatic_ipc227g_firmware`
- `simatic_ipc277g_firmware`
- `simatic_itp1000_firmware`
- `simatic_ipc477e_pro_firmware`
- `simatic_ipc627e_firmware`
- `simatic_ipc647e_firmware`
- `simatic_ipc677e_firmware`
- `simatic_ipc847e_firmware`
- `simatic_ipc327g_firmware`
- `simatic_ipc377g_firmware`
- `simatic_ipc427e_firmware`
- `simatic_ipc477e_firmware`
- `simatic_field_pg_m5_firmware`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
