GHSA-67f6-6h83-3w53HighCVSS 6.7
An issue was discovered in IdeBusDxe in Insyde InsydeH2O 5.x. Code in system management mode...
🔗 CVE IDs covered (1)
📋 Description
An issue was discovered in IdeBusDxe in Insyde InsydeH2O 5.x. Code in system management mode calls a function outside of SMRAM in response to a crafted software SMI, aka Inclusion of Functionality from an Untrusted Control Sphere. Modifying the well-known address of this function allows an attacker to gain control of the system with the privileges of system management mode.
🔗 References (8)
- https://nvd.nist.gov/vuln/detail/CVE-2020-27339
- https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf
- https://www.insyde.com/products
- https://www.insyde.com/security-pledge/SA-2021001
- https://security.netapp.com/advisory/ntap-20220216-0005
- https://www.kb.cert.org/vuls/id/796611
- https://cert-portal.siemens.com/productcert/html/ssa-306654.html
- https://github.com/advisories/GHSA-67f6-6h83-3w53