---
id: CVE-2021-33625
title: >-
  An issue was discovered in Kernel 5.x in Insyde InsydeH2O, affecting
  HddPassword
summary: >-
  An issue was discovered in Kernel 5.x in Insyde InsydeH2O, affecting
  HddPassword. Software SMI services that use the Communicate() function of the
  EFI_SMM_COMMUNICATION_PROTOCOL do not check whether the address of the buffer
  is valid, wh…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-119
vendor: insyde
product: insydeh2o
affected:
  - 'insydeh2o >= 5.1, < 5.16.23'
  - 'insydeh2o >= 5.2, < 5.26.23'
  - 'insydeh2o >= 5.3, < 5.35.23'
  - 'insydeh2o >= 5.4, < 5.43.22'
  - 'insydeh2o >= 5.5, < 5.51.22'
  - fas/aff_bios
  - ruggedcom_ape1808_firmware
  - simatic_field_pg_m5_firmware
  - simatic_ipc127e_firmware
  - simatic_itp1000_firmware
  - simatic_ipc277g_firmware
  - simatic_ipc227g_firmware
  - simatic_ipc327g_firmware
  - simatic_ipc377g_firmware
  - simatic_ipc427e_firmware
  - simatic_ipc477e_firmware
  - simatic_ipc477e_pro_firmware
  - simatic_ipc627e_firmware
  - simatic_ipc647e_firmware
  - simatic_ipc677e_firmware
  - simatic_ipc847e_firmware
  - simatic_field_pg_m6_firmware
patched:
  - insydeh2o 5.51.22
published: '2022-02-03'
updated: '2026-08-11'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-33625'
references:
  - url: 'https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf'
    label: cve@mitre.org
  - url: 'https://security.netapp.com/advisory/ntap-20220222-0004/'
    label: cve@mitre.org
  - url: 'https://www.insyde.com/security-pledge'
    label: cve@mitre.org
  - url: 'https://www.insyde.com/security-pledge/SA-2022014'
    label: cve@mitre.org
  - url: 'https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20220222-0004/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.insyde.com/security-pledge'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.insyde.com/security-pledge/SA-2022014'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.kb.cert.org/vuls/id/796611'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-306654.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
tags:
  - nvd
epss: 0.00315
epssPercentile: 0.21828
ingestedAt: '2026-08-11T16:47:01.739Z'
---

## Overview

An issue was discovered in Kernel 5.x in Insyde InsydeH2O, affecting HddPassword. Software SMI services that use the Communicate() function of the EFI_SMM_COMMUNICATION_PROTOCOL do not check whether the address of the buffer is valid, which allows use of SMRAM, MMIO, or OS kernel addresses.

## Affected

- `insydeh2o >= 5.1, < 5.16.23`
- `insydeh2o >= 5.2, < 5.26.23`
- `insydeh2o >= 5.3, < 5.35.23`
- `insydeh2o >= 5.4, < 5.43.22`
- `insydeh2o >= 5.5, < 5.51.22`
- `fas/aff_bios`
- `ruggedcom_ape1808_firmware`
- `simatic_field_pg_m5_firmware`
- `simatic_ipc127e_firmware`
- `simatic_itp1000_firmware`
- `simatic_ipc277g_firmware`
- `simatic_ipc227g_firmware`
- `simatic_ipc327g_firmware`
- `simatic_ipc377g_firmware`
- `simatic_ipc427e_firmware`
- `simatic_ipc477e_firmware`
- `simatic_ipc477e_pro_firmware`
- `simatic_ipc627e_firmware`
- `simatic_ipc647e_firmware`
- `simatic_ipc677e_firmware`
- `simatic_ipc847e_firmware`
- `simatic_field_pg_m6_firmware`

## Remediation

Upgrade past the affected range:

- `insydeh2o 5.51.22`
