---
id: CVE-2021-33626
title: >-
  A vulnerability exists in SMM (System Management Mode) branch that registers a
  SWSMI handler that does not sufficiently check or validate the allocated
  buffer pointer(QWORD values for CommBuffer)
summary: >-
  A vulnerability exists in SMM (System Management Mode) branch that registers a
  SWSMI handler that does not sufficiently check or validate the allocated
  buffer pointer(QWORD values for CommBuffer). This can be used by an attacker
  to corru…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-829
vendor: insyde
product: insydeh2o
affected:
  - 'insydeh2o >= 5.3, < 5.34.44'
  - 'insydeh2o >= 5.2, < 5.25.44'
  - 'insydeh2o >= 5.1, < 5.16.25'
  - 'insydeh2o >= 5.4, < 5.42.44'
  - 'insydeh2o >= 5.3, < 5.35.25'
  - 'insydeh2o >= 5.2, < 5.26.25'
  - 'insydeh2o >= 5.4, < 5.43.25'
  - ruggedcom_apr1808_firmware
  - simatic_field_pg_m5_firmware
  - simatic_field_pg_m6_firmware
  - simatic_ipc127e_firmware
  - simatic_ipc227g_firmware
  - simatic_ipc277g_firmware
  - simatic_ipc327g_firmware
  - simatic_ipc377g_firmware
  - simatic_ipc427e_firmware
  - simatic_ipc477e_firmware
  - simatic_ipc477e_pro_firmware
  - simatic_ipc627e_firmware
  - simatic_ipc647e_firmware
  - simatic_ipc677e_firmware
  - simatic_ipc847e_firmware
  - simatic_itp1000_firmware
patched:
  - insydeh2o 5.43.25
published: '2021-10-01'
updated: '2026-08-11'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-33626'
references:
  - url: 'https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf'
    label: cve@mitre.org
  - url: 'https://security.netapp.com/advisory/ntap-20220216-0006/'
    label: cve@mitre.org
  - url: 'https://www.insyde.com/security-pledge'
    label: cve@mitre.org
  - url: 'https://www.insyde.com/security-pledge/SA-2021001'
    label: cve@mitre.org
  - url: 'https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20220216-0006/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.insyde.com/security-pledge'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.insyde.com/security-pledge/SA-2021001'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.kb.cert.org/vuls/id/796611'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-306654.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
tags:
  - nvd
epss: 0.00308
epssPercentile: 0.21056
ingestedAt: '2026-08-11T16:47:01.478Z'
---

## Overview

A vulnerability exists in SMM (System Management Mode) branch that registers a SWSMI handler that does not sufficiently check or validate the allocated buffer pointer(QWORD values for CommBuffer). This can be used by an attacker to corrupt data in SMRAM memory and even lead to arbitrary code execution.

## Affected

- `insydeh2o >= 5.3, < 5.34.44`
- `insydeh2o >= 5.2, < 5.25.44`
- `insydeh2o >= 5.1, < 5.16.25`
- `insydeh2o >= 5.4, < 5.42.44`
- `insydeh2o >= 5.3, < 5.35.25`
- `insydeh2o >= 5.2, < 5.26.25`
- `insydeh2o >= 5.4, < 5.43.25`
- `ruggedcom_apr1808_firmware`
- `simatic_field_pg_m5_firmware`
- `simatic_field_pg_m6_firmware`
- `simatic_ipc127e_firmware`
- `simatic_ipc227g_firmware`
- `simatic_ipc277g_firmware`
- `simatic_ipc327g_firmware`
- `simatic_ipc377g_firmware`
- `simatic_ipc427e_firmware`
- `simatic_ipc477e_firmware`
- `simatic_ipc477e_pro_firmware`
- `simatic_ipc627e_firmware`
- `simatic_ipc647e_firmware`
- `simatic_ipc677e_firmware`
- `simatic_ipc847e_firmware`
- `simatic_itp1000_firmware`

## Remediation

Upgrade past the affected range:

- `insydeh2o 5.43.25`
