7.8
CVE-2021-33626
- EPSS 0.08%
- Published 01.10.2021 03:15:06
- Last modified 21.11.2024 06:09:13
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
A vulnerability exists in SMM (System Management Mode) branch that registers a SWSMI handler that does not sufficiently check or validate the allocated buffer pointer(QWORD values for CommBuffer). This can be used by an attacker to corrupt data in SMRAM memory and even lead to arbitrary code execution.
Data is provided by the National Vulnerability Database (NVD)
Siemens ≫ Ruggedcom Apr1808 Firmware Version-
Siemens ≫ Simatic Field Pg M5 Firmware Version-
Siemens ≫ Simatic Field Pg M6 Firmware Version-
Siemens ≫ Simatic Ipc127e Firmware Version-
Siemens ≫ Simatic Ipc227g Firmware Version-
Siemens ≫ Simatic Ipc277g Firmware Version-
Siemens ≫ Simatic Ipc327g Firmware Version-
Siemens ≫ Simatic Ipc377g Firmware Version-
Siemens ≫ Simatic Ipc427e Firmware Version-
Siemens ≫ Simatic Ipc477e Firmware Version-
Siemens ≫ Simatic Ipc477e Pro Firmware Version-
Siemens ≫ Simatic Ipc627e Firmware Version-
Siemens ≫ Simatic Ipc647e Firmware Version-
Siemens ≫ Simatic Ipc677e Firmware Version-
Siemens ≫ Simatic Ipc847e Firmware Version-
Siemens ≫ Simatic Itp1000 Firmware Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.08% | 0.25 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 4.6 | 3.9 | 6.4 |
AV:L/AC:L/Au:N/C:P/I:P/A:P
|
CWE-829 Inclusion of Functionality from Untrusted Control Sphere
The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.