CVE-2020-5953

A vulnerability exists in System Management Interrupt (SWSMI) handler of InsydeH2O UEFI Firmware code located in SWSMI handler that dereferences gRT (EFI_RUNTIME_SERVICES) pointer to call a GetVariable service, which is located outside of SMRAM. This can result in code execution in SMM (escalating privilege from ring 0 to ring -2).
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:insyde:insydeh2o:5.12.09.0074:*:*:*:*:*:*:*
cpe:2.3:a:insyde:insydeh2o:5.23.04.0045:*:*:*:*:*:*:*
cpe:2.3:a:insyde:insydeh2o:5.23.45.0023:*:*:*:*:*:*:*
cpe:2.3:a:insyde:insydeh2o:5.33.15.0034:*:*:*:*:*:*:*
cpe:2.3:a:insyde:insydeh2o:5.34.03.0029:*:*:*:*:*:*:*
cpe:2.3:a:insyde:insydeh2o:5.42.03.0010:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:siemens:ruggedcom_ape1808_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:ruggedcom_ape1808:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:siemens:simatic_field_pg_m6_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_field_pg_m6:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc127e_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc127e:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc227g_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc227g:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc277g_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc277g:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:siemens:simatic_itp1000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_itp1000:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc477e_pro_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc477e_pro:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc627e_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc627e:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc647e_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc647e:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc677e_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc677e:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc847e_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc847e:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc327g_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc327g:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc377g_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc377g:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc427e_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc427e:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc477e_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc477e:-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
cpe:2.3:o:siemens:simatic_field_pg_m5_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_field_pg_m5:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2022-02-03 01:15

Updated : 2024-02-28 18:48


NVD link : CVE-2020-5953

Mitre link : CVE-2020-5953

CVE.ORG link : CVE-2020-5953


JSON object : View

Products Affected

siemens

  • simatic_ipc427e
  • simatic_ipc627e
  • simatic_ipc227g_firmware
  • simatic_ipc477e
  • simatic_field_pg_m6
  • simatic_ipc377g_firmware
  • simatic_field_pg_m5
  • simatic_ipc647e_firmware
  • simatic_ipc127e_firmware
  • simatic_field_pg_m6_firmware
  • simatic_itp1000_firmware
  • ruggedcom_ape1808
  • simatic_ipc627e_firmware
  • simatic_ipc377g
  • simatic_ipc847e_firmware
  • simatic_ipc477e_firmware
  • simatic_ipc277g
  • simatic_ipc277g_firmware
  • simatic_ipc477e_pro
  • simatic_field_pg_m5_firmware
  • simatic_ipc677e_firmware
  • simatic_ipc647e
  • simatic_ipc677e
  • simatic_ipc327g
  • ruggedcom_ape1808_firmware
  • simatic_ipc227g
  • simatic_ipc127e
  • simatic_ipc477e_pro_firmware
  • simatic_ipc427e_firmware
  • simatic_ipc847e
  • simatic_itp1000
  • simatic_ipc327g_firmware

insyde

  • insydeh2o