---
id: CVE-2021-43522
title: >-
  An issue was discovered in Insyde InsydeH2O with kernel 5.1 through
  2021-11-08, 5.2 through 2021-11-08, and 5.3 through 2021-11-08
summary: >-
  An issue was discovered in Insyde InsydeH2O with kernel 5.1 through
  2021-11-08, 5.2 through 2021-11-08, and 5.3 through 2021-11-08. A
  StorageSecurityCommandDxe SMM memory corruption vulnerability allows an
  attacker to write fixed or pred…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-787
vendor: insyde
product: insydeh2o
affected:
  - 'insydeh2o >= 5.1, < 5.14.34'
  - 'insydeh2o >= 5.2, < 5.24.34'
  - 'insydeh2o >= 5.3, < 5.33.34'
patched:
  - insydeh2o 5.33.34
published: '2022-02-03'
updated: '2026-08-11'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-43522'
references:
  - url: 'https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf'
    label: cve@mitre.org
  - url: 'https://security.netapp.com/advisory/ntap-20220216-0003/'
    label: cve@mitre.org
  - url: 'https://www.insyde.com/security-pledge'
    label: cve@mitre.org
  - url: 'https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20220216-0003/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.insyde.com/security-pledge'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.kb.cert.org/vuls/id/796611'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-306654.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
tags:
  - nvd
epss: 0.00264
epssPercentile: 0.16264
ingestedAt: '2026-08-11T16:47:01.627Z'
---

## Overview

An issue was discovered in Insyde InsydeH2O with kernel 5.1 through 2021-11-08, 5.2 through 2021-11-08, and 5.3 through 2021-11-08. A StorageSecurityCommandDxe SMM memory corruption vulnerability allows an attacker to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM.

## Affected

- `insydeh2o >= 5.1, < 5.14.34`
- `insydeh2o >= 5.2, < 5.24.34`
- `insydeh2o >= 5.3, < 5.33.34`

## Remediation

Upgrade past the affected range:

- `insydeh2o 5.33.34`
