CVE-2021-42113
Last modified
CVE-2021-42113 is a high-severity vulnerability rated 8.2/10 on the CVSS scale. An issue was discovered in StorageSecurityCommandDxe in Insyde InsydeH2O with Kernel 5.1 before 05.14.28, Kernel 5.2 before 05.24.28, and Kernel 5.3 before 05.32.25. An SMM callout vulnerability allows an attacker to hijack execution flow of code running in System Management Mode. EPSS estimates a 0.30% chance of exploitation in the next 30 days.
Description
An issue was discovered in StorageSecurityCommandDxe in Insyde InsydeH2O with Kernel 5.1 before 05.14.28, Kernel 5.2 before 05.24.28, and Kernel 5.3 before 05.32.25. An SMM callout vulnerability allows an attacker to hijack execution flow of code running in System Management Mode. Exploiting this issue could lead to escalating privileges to SMM.
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Insyde | Insydeh2o | >= 5.1, < 5.14.34 |
| Insyde | Insydeh2o | >= 5.2, < 5.24.34 |
| Insyde | Insydeh2o | >= 5.3, < 5.24.34 |
References
- https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdfThird Party Advisory
- https://security.netapp.com/advisory/ntap-20220216-0012/Third Party Advisory
- https://www.insyde.com/security-pledgeVendor Advisory
- https://www.insyde.com/security-pledge/SA-2022008Vendor Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdfThird Party Advisory
- https://security.netapp.com/advisory/ntap-20220216-0012/Third Party Advisory
- https://www.insyde.com/security-pledgeVendor Advisory
- https://www.insyde.com/security-pledge/SA-2022008Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-42113?
How severe is CVE-2021-42113?
How do I fix CVE-2021-42113?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-42108Unnecessary privilege vulnerabilities in the Web Console of …7.8
- CVE-2021-42109VITEC Exterity IPTV products through 2021-04-30 allow privil…9.8
- CVE-2021-4211A potential vulnerability in the SMI callback function used …6.7
- CVE-2021-42110An issue was discovered in Allegro Windows (formerly Popsy W…7.8
- CVE-2021-42111An issue was discovered in the RCDevs OpenOTP app 1.4.13 and…5.5
- CVE-2021-42112The "File upload question" functionality in LimeSurvey 3.x-L…6.1
- CVE-2021-42114Modern DRAM devices (PC-DDR4, LPDDR4X) are affected by a vul…8.3
- CVE-2021-42115Missing HTTPOnly flag in Web Applications operating on Busin…9.1
- CVE-2021-42116Incorrect Access Control in Web Applications operating on Bu…4.3
- CVE-2021-42117Insufficient Input Validation in Web Applications operating …5.4
- CVE-2021-42118Persistent Cross Site Scripting in Web Applications operatin…5.4
- CVE-2021-42119Persistent Cross Site Scripting in Web Applications operatin…5.4
Are you affected by CVE-2021-42113?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
