CVE-2021-33625High· 7.5▾ TwilightAn issue was discovered in Kernel 5.x in Insyde InsydeH2O, affecting HddPassword. Software SMI services that use the Communicate() function of the EFI_SMM_COMMUNICATION_PROTOCOL do not check whether the address of the buffer is valid, wh…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 11.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
0.3% → 0.3%
An issue was discovered in Kernel 5.x in Insyde InsydeH2O, affecting HddPassword. Software SMI services that use the Communicate() function of the EFI_SMM_COMMUNICATION_PROTOCOL do not check whether the address of the buffer is valid, which allows use of SMRAM, MMIO, or OS kernel addresses.
insydeh2o >= 5.1, < 5.16.23insydeh2o >= 5.2, < 5.26.23insydeh2o >= 5.3, < 5.35.23insydeh2o >= 5.4, < 5.43.22insydeh2o >= 5.5, < 5.51.22fas/aff_biosruggedcom_ape1808_firmwaresimatic_field_pg_m5_firmwaresimatic_ipc127e_firmwaresimatic_itp1000_firmwaresimatic_ipc277g_firmwaresimatic_ipc227g_firmwaresimatic_ipc327g_firmwaresimatic_ipc377g_firmwaresimatic_ipc427e_firmwaresimatic_ipc477e_firmwaresimatic_ipc477e_pro_firmwaresimatic_ipc627e_firmwaresimatic_ipc647e_firmwaresimatic_ipc677e_firmwaresimatic_ipc847e_firmwaresimatic_field_pg_m6_firmwareUpgrade past the affected range:
insydeh2o 5.51.22Connected by shared product, vendor, weakness, or advisory.
CVE-2021-41839High· 8.2An issue was discovered in NvmExpressDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O
CVE-2021-41838High· 8.2An issue was discovered in SdHostDriver in the kernel 5.0 through 5.5 in Insyde InsydeH2O
CVE-2021-41837High· 8.2An issue was discovered in AhciBusDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O
CVE-2021-33627High· 8.2An issue was discovered in Insyde InsydeH2O Kernel 5.0 before 05.09.11, 5.1 before 05.17.11, 5.2 before 05.27.11, 5.3 before 05.36.11, 5.4 before 05.44.11, and 5.5 before 05.52.11 affecting FwBlockServiceSmm
CVE-2022-24031High· 8.2An issue was discovered in NvmExpressDxe in Insyde InsydeH2O with kernel 5.1 through 5.5
CVE-2022-24030High· 7.5An issue was discovered in AhciBusDxe in Insyde InsydeH2O with kernel 5.1 through 5.5