7.5

CVE-2020-5953

A vulnerability exists in System Management Interrupt (SWSMI) handler of InsydeH2O UEFI Firmware code located in SWSMI handler that dereferences gRT (EFI_RUNTIME_SERVICES) pointer to call a GetVariable service, which is located outside of SMRAM. This can result in code execution in SMM (escalating privilege from ring 0 to ring -2).

Data is provided by the National Vulnerability Database (NVD)
InsydeInsydeh2o Version5.12.09.0074
InsydeInsydeh2o Version5.23.04.0045
InsydeInsydeh2o Version5.23.45.0023
InsydeInsydeh2o Version5.33.15.0034
InsydeInsydeh2o Version5.34.03.0029
InsydeInsydeh2o Version5.42.03.0010
SiemensSimatic Ipc127e Firmware Version-
   SiemensSimatic Ipc127e Version-
SiemensSimatic Ipc227g Firmware Version-
   SiemensSimatic Ipc227g Version-
SiemensSimatic Ipc277g Firmware Version-
   SiemensSimatic Ipc277g Version-
SiemensSimatic Itp1000 Firmware Version-
   SiemensSimatic Itp1000 Version-
SiemensSimatic Ipc627e Firmware Version-
   SiemensSimatic Ipc627e Version-
SiemensSimatic Ipc647e Firmware Version-
   SiemensSimatic Ipc647e Version-
SiemensSimatic Ipc677e Firmware Version-
   SiemensSimatic Ipc677e Version-
SiemensSimatic Ipc847e Firmware Version-
   SiemensSimatic Ipc847e Version-
SiemensSimatic Ipc327g Firmware Version-
   SiemensSimatic Ipc327g Version-
SiemensSimatic Ipc377g Firmware Version-
   SiemensSimatic Ipc377g Version-
SiemensSimatic Ipc427e Firmware Version-
   SiemensSimatic Ipc427e Version-
SiemensSimatic Ipc477e Firmware Version-
   SiemensSimatic Ipc477e Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.29% 0.523
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 0.8 6
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
nvd@nist.gov 6.9 3.4 10
AV:L/AC:M/Au:N/C:C/I:C/A:C