9.8

CVE-2021-41842

An issue was discovered in AtaLegacySmm in the kernel 5.0 before 05.08.46, 5.1 before 05.16.46, 5.2 before 05.26.46, 5.3 before 05.35.46, 5.4 before 05.43.46, and 5.5 before 05.51.45 in Insyde InsydeH2O. Code execution can occur because the SMI handler lacks a CommBuffer check.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
InsydeInsydeh2o Version >= 5.0 < 05.08.46
InsydeInsydeh2o Version >= 5.1 < 05.16.46
InsydeInsydeh2o Version >= 5.2 < 05.26.46
InsydeInsydeh2o Version >= 5.3 < 05.35.46
InsydeInsydeh2o Version > 5.4 < 05.43.46
InsydeInsydeh2o Version >= 5.5 < 05.51.45
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.22% 0.771
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P