CVE-2020-5953
Last modified
CVE-2020-5953 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. A vulnerability exists in System Management Interrupt (SWSMI) handler of InsydeH2O UEFI Firmware code located in SWSMI handler that dereferences gRT (EFI_RUNTIME_SERVICES) pointer to call a GetVariable service, which is located outside of SMRAM. This can result in code execution in SMM (escalating privilege from ring 0 to ring -2).. EPSS estimates a 0.28% chance of exploitation in the next 30 days.
Description
A vulnerability exists in System Management Interrupt (SWSMI) handler of InsydeH2O UEFI Firmware code located in SWSMI handler that dereferences gRT (EFI_RUNTIME_SERVICES) pointer to call a GetVariable service, which is located outside of SMRAM. This can result in code execution in SMM (escalating privilege from ring 0 to ring -2).
Metrics
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Insyde | Insydeh2o | 5.12.09.0074 |
| Insyde | Insydeh2o | 5.23.04.0045 |
| Insyde | Insydeh2o | 5.23.45.0023 |
| Insyde | Insydeh2o | 5.33.15.0034 |
| Insyde | Insydeh2o | 5.34.03.0029 |
| Insyde | Insydeh2o | 5.42.03.0010 |
| Siemens | Ruggedcom Ape1808 Firmware | All versions |
| Siemens | Simatic Field Pg M6 Firmware | All versions |
| Siemens | Simatic Ipc127e Firmware | All versions |
| Siemens | Simatic Ipc227g Firmware | All versions |
| Siemens | Simatic Ipc277g Firmware | All versions |
| Siemens | Simatic Itp1000 Firmware | All versions |
| Siemens | Simatic Ipc477e Pro Firmware | All versions |
| Siemens | Simatic Ipc627e Firmware | All versions |
| Siemens | Simatic Ipc647e Firmware | All versions |
| Siemens | Simatic Ipc677e Firmware | All versions |
| Siemens | Simatic Ipc847e Firmware | All versions |
| Siemens | Simatic Ipc327g Firmware | All versions |
| Siemens | Simatic Ipc377g Firmware | All versions |
| Siemens | Simatic Ipc427e Firmware | All versions |
| Siemens | Simatic Ipc477e Firmware | All versions |
| Siemens | Simatic Field Pg M5 Firmware | All versions |
References
- https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdfThird Party Advisory
- https://security.netapp.com/advisory/ntap-20220222-0005/Third Party Advisory
- https://www.insyde.com/productsProduct, Vendor Advisory
- https://www.insyde.com/security-pledgeVendor Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdfThird Party Advisory
- https://security.netapp.com/advisory/ntap-20220222-0005/Third Party Advisory
- https://www.insyde.com/productsProduct, Vendor Advisory
- https://www.insyde.com/security-pledgeVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-5953?
How severe is CVE-2020-5953?
How do I fix CVE-2020-5953?
Are you affected by CVE-2020-5953?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
