CVE-2020-5956
Last modified
CVE-2020-5956 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. An issue was discovered in SdLegacySmm in Insyde InsydeH2O with kernel 5.1 before 05.15.11, 5.2 before 05.25.11, 5.3 before 05.34.11, and 5.4 before 05.42.11. The software SMI handler allows untrusted external input because it does not verify CommBuffer.. EPSS estimates a 0.81% chance of exploitation in the next 30 days.
Description
An issue was discovered in SdLegacySmm in Insyde InsydeH2O with kernel 5.1 before 05.15.11, 5.2 before 05.25.11, 5.3 before 05.34.11, and 5.4 before 05.42.11. The software SMI handler allows untrusted external input because it does not verify CommBuffer.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Insyde | Insydeh2o | >= 5.2, < 5.25.11 |
| Insyde | Insydeh2o | >= 5.1, < 05.15.11 |
| Insyde | Insydeh2o | >= 5.3, < 05.34.11 |
| Insyde | Insydeh2o | >= 5.4, < 05.42.11 |
References
- https://security.netapp.com/advisory/ntap-20220223-0001/Third Party Advisory
- https://www.insyde.com/security-pledgeVendor Advisory
- https://security.netapp.com/advisory/ntap-20220223-0001/Third Party Advisory
- https://www.insyde.com/security-pledgeVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-5956?
How severe is CVE-2020-5956?
How do I fix CVE-2020-5956?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-5947In versions 16.0.0-16.0.0.1 and 15.1.0-15.1.1, on specific B…4.3
- CVE-2020-5948On BIG-IP versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-…9.6
- CVE-2020-5949On BIG-IP versions 14.0.0-14.0.1 and 13.1.0-13.1.3.4, certai…7.5
- CVE-2020-5950On BIG-IP 14.1.0-14.1.2.6, undisclosed endpoints in iControl…5.3
- CVE-2020-5953A vulnerability exists in System Management Interrupt (SWSMI…7.5
- CVE-2020-5955An issue was discovered in Int15MicrocodeSmm in Insyde Insyd…9.8
- CVE-2020-5957NVIDIA Windows GPU Display Driver, all versions, contains a …7.8
- CVE-2020-5958NVIDIA Windows GPU Display Driver, all versions, contains a …7.8
- CVE-2020-5959NVIDIA Virtual GPU Manager, all versions, contains a vulnera…5.5
- CVE-2020-5960NVIDIA Virtual GPU Manager contains a vulnerability in the k…5.5
- CVE-2020-5961NVIDIA vGPU graphics driver for guest OS contains a vulnerab…5.5
- CVE-2020-5962NVIDIA Windows GPU Display Driver, all versions, contains a …7.8
Are you affected by CVE-2020-5956?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
