---
id: CVE-2021-41840
title: >-
  An issue was discovered in NvmExpressDxe in the kernel 5.0 through 5.5 in
  Insyde InsydeH2O
summary: >-
  An issue was discovered in NvmExpressDxe in the kernel 5.0 through 5.5 in
  Insyde InsydeH2O. There is an SMM callout that allows an attacker to access
  the System Management Mode and execute arbitrary code. This occurs because of
  Inclusion…
severity: high
cvss: 8.2
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-770
vendor: insyde
product: insydeh2o
affected:
  - 'insydeh2o >= 5.2, < 5.23.35'
  - 'insydeh2o >= 5.3, < 5.32.35'
  - 'insydeh2o >= 5.4, < 5.40.35'
patched:
  - insydeh2o 5.40.35
published: '2022-02-03'
updated: '2026-08-11'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-41840'
references:
  - url: 'https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf'
    label: cve@mitre.org
  - url: 'https://security.netapp.com/advisory/ntap-20220217-0014/'
    label: cve@mitre.org
  - url: 'https://www.insyde.com/security-pledge'
    label: cve@mitre.org
  - url: 'https://www.insyde.com/security-pledge/SA-2022018'
    label: cve@mitre.org
  - url: 'https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20220217-0014/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.insyde.com/security-pledge'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.insyde.com/security-pledge/SA-2022018'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.kb.cert.org/vuls/id/796611'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-306654.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
tags:
  - nvd
epss: 0.00303
epssPercentile: 0.23226
ingestedAt: '2026-08-11T16:47:02.083Z'
---

## Overview

An issue was discovered in NvmExpressDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. There is an SMM callout that allows an attacker to access the System Management Mode and execute arbitrary code. This occurs because of Inclusion of Functionality from an Untrusted Control Sphere.

## Affected

- `insydeh2o >= 5.2, < 5.23.35`
- `insydeh2o >= 5.3, < 5.32.35`
- `insydeh2o >= 5.4, < 5.40.35`

## Remediation

Upgrade past the affected range:

- `insydeh2o 5.40.35`
