7.5
CVE-2021-33625
- EPSS 0.07%
- Published 03.02.2022 02:15:06
- Last modified 21.11.2024 06:09:13
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
An issue was discovered in Kernel 5.x in Insyde InsydeH2O, affecting HddPassword. Software SMI services that use the Communicate() function of the EFI_SMM_COMMUNICATION_PROTOCOL do not check whether the address of the buffer is valid, which allows use of SMRAM, MMIO, or OS kernel addresses.
Data is provided by the National Vulnerability Database (NVD)
Netapp ≫ Fas/aff Bios Version-
Siemens ≫ Ruggedcom Ape1808 Firmware Version-
Siemens ≫ Simatic Field Pg M5 Firmware Version-
Siemens ≫ Simatic Ipc127e Firmware Version-
Siemens ≫ Simatic Itp1000 Firmware Version-
Siemens ≫ Simatic Ipc277g Firmware Version-
Siemens ≫ Simatic Ipc227g Firmware Version-
Siemens ≫ Simatic Ipc327g Firmware Version-
Siemens ≫ Simatic Ipc377g Firmware Version-
Siemens ≫ Simatic Ipc427e Firmware Version-
Siemens ≫ Simatic Ipc477e Firmware Version-
Siemens ≫ Simatic Ipc477e Pro Firmware Version-
Siemens ≫ Simatic Ipc627e Firmware Version-
Siemens ≫ Simatic Ipc647e Firmware Version-
Siemens ≫ Simatic Ipc677e Firmware Version-
Siemens ≫ Simatic Ipc847e Firmware Version-
Siemens ≫ Simatic Field Pg M6 Firmware Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.07% | 0.21 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 0.8 | 6 |
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
|
nvd@nist.gov | 6.9 | 3.4 | 10 |
AV:L/AC:M/Au:N/C:C/I:C/A:C
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.