9.8

CVE-2021-41842

An issue was discovered in AtaLegacySmm in the kernel 5.0 before 05.08.46, 5.1 before 05.16.46, 5.2 before 05.26.46, 5.3 before 05.35.46, 5.4 before 05.43.46, and 5.5 before 05.51.45 in Insyde InsydeH2O. Code execution can occur because the SMI handler lacks a CommBuffer check.

Data is provided by the National Vulnerability Database (NVD)
InsydeInsydeh2o Version >= 5.0 < 05.08.46
InsydeInsydeh2o Version >= 5.1 < 05.16.46
InsydeInsydeh2o Version >= 5.2 < 05.26.46
InsydeInsydeh2o Version >= 5.3 < 05.35.46
InsydeInsydeh2o Version > 5.4 < 05.43.46
InsydeInsydeh2o Version >= 5.5 < 05.51.45
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.22% 0.771
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P