8.8

CVE-2022-29277

Incorrect pointer checks within the the FwBlockServiceSmm driver can allow arbitrary RAM modifications During review of the FwBlockServiceSmm driver, certain instances of SpiAccessLib could be tricked into writing 0xff to arbitrary system and SMRAM addresses. Fixed in: INTEL Purley-R: 05.21.51.0048 Whitley: 05.42.23.0066 Cedar Island: 05.42.11.0021 Eagle Stream: 05.44.25.0052 Greenlow/Greenlow-R(skylake/kabylake): Trunk Mehlow/Mehlow-R (CoffeeLake-S): Trunk Tatlow (RKL-S): Trunk Denverton: 05.10.12.0042 Snow Ridge: Trunk Graneville DE: 05.05.15.0038 Grangeville DE NS: 05.27.26.0023 Bakerville: 05.21.51.0026 Idaville: 05.44.27.0030 Whiskey Lake: Trunk Comet Lake-S: Trunk Tiger Lake H/UP3: 05.43.12.0052 Alder Lake: 05.44.23.0047 Gemini Lake: Not Affected Apollo Lake: Not Affected Elkhart Lake: 05.44.30.0018 AMD ROME: trunk MILAN: 05.36.10.0017 GENOA: 05.52.25.0006 Snowy Owl: Trunk R1000: 05.32.50.0018 R2000: 05.44.30.0005 V2000: Trunk V3000: 05.44.30.0007 Ryzen 5000: 05.44.30.0004 Embedded ROME: Trunk Embedded MILAN: Trunk Hygon Hygon #1/#2: 05.36.26.0016 Hygon #3: 05.44.26.0007 https://www.insyde.com/security-pledge/SA-2022060

Data is provided by the National Vulnerability Database (NVD)
AmdGenoa Firmware Version < 05.52.25.0006
   AmdGenoa Version-
AmdHygon 1 Firmware Version < 05.36.26.0016
   AmdHygon 1 Version-
AmdHygon 2 Firmware Version < 05.36.26.0016
   AmdHygon 2 Version-
AmdHygon 3 Firmware Version < 05.44.26.0007
   AmdHygon 3 Version-
AmdMilan Firmware Version < 05.36.10.0017
   AmdMilan Version-
AmdMilan Firmware SwEditionembedded Version < 05.36.26.0016
   AmdMilan Version- SwEditionembedded
AmdRome Firmware Version < 05.36.10.0017
   AmdRome Version-
AmdRome Firmware SwEditionembedded Version < 05.36.26.0016
   AmdRome Version- SwEditionembedded
AmdRyzen 5300g Firmware Version < 05.44.30.0004
   AmdRyzen 5300g Version-
AmdRyzen 5300ge Firmware Version < 05.44.30.0004
   AmdRyzen 5300ge Version-
AmdRyzen 5600g Firmware Version < 05.44.30.0004
   AmdRyzen 5600g Version-
AmdRyzen 5600ge Firmware Version < 05.44.30.0004
   AmdRyzen 5600ge Version-
AmdRyzen 5600x Firmware Version < 05.44.30.0004
   AmdRyzen 5600x Version-
AmdRyzen 5700g Firmware Version < 05.44.30.0004
   AmdRyzen 5700g Version-
AmdRyzen 5700ge Firmware Version < 05.44.30.0004
   AmdRyzen 5700ge Version-
AmdRyzen 5800x Firmware Version < 05.44.30.0004
   AmdRyzen 5800x Version-
AmdRyzen 5800x3d Firmware Version < 05.44.30.0004
   AmdRyzen 5800x3d Version-
AmdRyzen 5900x Firmware Version < 05.44.30.0004
   AmdRyzen 5900x Version-
AmdRyzen 5950x Firmware Version < 05.44.30.0004
   AmdRyzen 5950x Version-
AmdSnowy Owl R1000 Firmware Version < 05.32.50.0018
   AmdSnowy Owl R1000 Version-
AmdSnowy Owl R2000 Firmware Version < 05.44.30.0005
   AmdSnowy Owl R2000 Version-
AmdSnowy Owl V2000 Firmware Version < 05.44.30.0007
   AmdSnowy Owl V2000 Version-
AmdSnowy Owl V3000 Firmware Version < 05.44.30.0007
   AmdSnowy Owl V3000 Version-
IntelAlder Lake Firmware Version < 05.44.23.0047
   IntelAlder Lake Version-
IntelBakerville Firmware Version < 05.21.51.0026
   IntelBakerville Version-
IntelCedar Island Firmware Version < 05.42.11.0021
   IntelCedar Island Version-
IntelIdaville Firmware Version < 05.43.12.0052
   IntelIdaville Version-
IntelComet Lake-s Firmware Version < 05.43.12.0052
   IntelComet Lake-s Version-
IntelWhiskey Lake Firmware Version < 05.43.12.0052
   IntelWhiskey Lake Version-
IntelDenverton Firmware Version < 05.10.12.0042
   IntelDenverton Version-
IntelEagle Stream Firmware Version < 05.44.25.0052
   IntelEagle Stream Version-
IntelGrangeville De Ns Firmware Version < 05.27.26.0023
   IntelGrangeville De Ns Version-
IntelGranville De Firmware Version < 05.05.15.0038
   IntelGranville De Version-
IntelGreenlow Firmware Version < 05.10.12.0042
   IntelGreenlow Version-
IntelGreenlow-r Firmware Version < 05.10.12.0042
   IntelGreenlow-r Version-
IntelMehlow Firmware Version < 05.10.12.0042
   IntelMehlow Version-
IntelMehlow-r Firmware Version < 05.10.12.0042
   IntelMehlow-r Version-
IntelTatlow Firmware Version < 05.10.12.0042
   IntelTatlow Version-
IntelPurley-r Firmware Version < 05.21.51.0048
   IntelPurley-r Version-
IntelWhitley Firmware Version < 05.42.23.0066
   IntelWhitley Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.07% 0.225
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.8 2 6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
134c704f-9b21-4f2e-91b3-4a467353bcc0 8.8 2 6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.