Vulnerability Name: CVE-2020-27339 (CCN-204398) Assigned: 2020-10-20 Published: 2021-06-14 Updated: 2022-07-12 Summary: In the kernel in Insyde InsydeH2O 5.x, certain SMM drivers did not correctly validate the CommBuffer and CommBufferSize parameters, allowing callers to corrupt either the firmware or the OS memory. The fixed versions for this issue in the AhciBusDxe, IdeBusDxe, NvmExpressDxe, SdHostDriverDxe, and SdMmcDeviceDxe drivers are 05.16.25, 05.26.25, 05.35.25, 05.43.25, and 05.51.25 (for Kernel 5.1 through 5.5). CVSS v3 Severity: 6.7 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H )5.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C )Exploitability Metrics: Attack Vector (AV): LocalAttack Complexity (AC): LowPrivileges Required (PR): HighUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): HighIntegrity (I): HighAvailibility (A): High
7.2 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N )6.3 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C )Exploitability Metrics: Attack Vector (AV): LocalAttack Complexity (AC): HighPrivileges Required (PR): HighUser Interaction (UI): NoneScope: Scope (S): ChangedImpact Metrics: Confidentiality (C): HighIntegrity (I): HighAvailibility (A): None
CVSS v2 Severity: 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C )Exploitability Metrics: Access Vector (AV): LocalAccess Complexity (AC): LowAuthentication (Au): NoneImpact Metrics: Confidentiality (C): CompleteIntegrity (I): CompleteAvailibility (A): Complete
5.5 Medium (CCN CVSS v2 Vector: AV:L/AC:H/Au:S/C:C/I:C/A:N )Exploitability Metrics: Access Vector (AV): LocalAccess Complexity (AC): HighAthentication (Au): Single_InstanceImpact Metrics: Confidentiality (C): CompleteIntegrity (I): CompleteAvailibility (A): None
Vulnerability Type: CWE-20 Vulnerability Consequences: Bypass Security References: Source: MITRE Type: CNACVE-2020-27339 Source: CONFIRM Type: Third Party Advisoryhttps://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf Source: XF Type: UNKNOWNinsyde-cve202027339-priv-esc(204398) Source: CONFIRM Type: Third Party Advisoryhttps://security.netapp.com/advisory/ntap-20220216-0005/ Source: CCN Type: INSYDE-SA-2021001Insyde Software Security Advisory Source: MISC Type: Vendor Advisoryhttps://www.insyde.com/security-pledge/SA-2021001 Vulnerable Configuration: Configuration 1 :cpe:/o:insyde:insydeh2o:*:*:*:*:*:*:*:* (Version >= 5.3 and < 5.34.44)Configuration 2 :cpe:/o:insyde:insydeh2o:*:*:*:*:*:*:*:* (Version >= 5.2 and < 5.25.44)Configuration 3 :cpe:/o:insyde:insydeh2o:*:*:*:*:*:*:*:* (Version >= 5.1 and < 5.16.25)Configuration 4 :cpe:/o:insyde:insydeh2o:*:*:*:*:*:*:*:* (Version >= 5.4 and < 5.42.44)Configuration 5 :cpe:/o:insyde:insydeh2o:*:*:*:*:*:*:*:* (Version >= 5.3 and < 5.35.25)Configuration 6 :cpe:/o:insyde:insydeh2o:*:*:*:*:*:*:*:* (Version >= 5.2 and < 5.26.25)Configuration 7 :cpe:/o:insyde:insydeh2o:*:*:*:*:*:*:*:* (Version >= 5.4 and < 5.43.25)Configuration 8 :cpe:/o:siemens:ruggedcom_apr1808_firmware:-:*:*:*:*:*:*:* AND cpe:/h:siemens:ruggedcom_apr1808:-:*:*:*:*:*:*:* Configuration 9 :cpe:/o:siemens:simatic_field_pg_m5_firmware:-:*:*:*:*:*:*:* AND cpe:/h:siemens:simatic_field_pg_m5:-:*:*:*:*:*:*:* Configuration 10 :cpe:/o:siemens:simatic_field_pg_m6_firmware:-:*:*:*:*:*:*:* AND cpe:/h:siemens:simatic_field_pg_m6:-:*:*:*:*:*:*:* Configuration 11 :cpe:/o:siemens:simatic_ipc127e_firmware:-:*:*:*:*:*:*:* AND cpe:/h:siemens:simatic_ipc127e:-:*:*:*:*:*:*:* Configuration 12 :cpe:/o:siemens:simatic_ipc227g_firmware:-:*:*:*:*:*:*:* AND cpe:/h:siemens:simatic_ipc227g:-:*:*:*:*:*:*:* Configuration 13 :cpe:/o:siemens:simatic_ipc277g_firmware:-:*:*:*:*:*:*:* AND cpe:/h:siemens:simatic_ipc277g:-:*:*:*:*:*:*:* Configuration 14 :cpe:/o:siemens:simatic_ipc327g_firmware:-:*:*:*:*:*:*:* AND cpe:/h:siemens:simatic_ipc327g:-:*:*:*:*:*:*:* Configuration 15 :cpe:/o:siemens:simatic_ipc377g_firmware:-:*:*:*:*:*:*:* AND cpe:/h:siemens:simatic_ipc377g:-:*:*:*:*:*:*:* Configuration 16 :cpe:/o:siemens:simatic_ipc427e_firmware:-:*:*:*:*:*:*:* AND cpe:/h:siemens:simatic_ipc427e:-:*:*:*:*:*:*:* Configuration 17 :cpe:/o:siemens:simatic_ipc477e_firmware:-:*:*:*:*:*:*:* AND cpe:/h:siemens:simatic_ipc477e:-:*:*:*:*:*:*:* Configuration 18 :cpe:/o:siemens:simatic_ipc477e_pro_firmware:-:*:*:*:*:*:*:* AND cpe:/h:siemens:simatic_ipc477e_pro:-:*:*:*:*:*:*:* Configuration 19 :cpe:/o:siemens:simatic_ipc627e_firmware:-:*:*:*:*:*:*:* AND cpe:/h:siemens:simatic_ipc627e:-:*:*:*:*:*:*:* Configuration 20 :cpe:/o:siemens:simatic_ipc647e_firmware:-:*:*:*:*:*:*:* AND cpe:/h:siemens:simatic_ipc647e:-:*:*:*:*:*:*:* Configuration 21 :cpe:/o:siemens:simatic_ipc677e_firmware:-:*:*:*:*:*:*:* AND cpe:/h:siemens:simatic_ipc677e:-:*:*:*:*:*:*:* Configuration 22 :cpe:/o:siemens:simatic_ipc847e_firmware:-:*:*:*:*:*:*:* AND cpe:/h:siemens:simatic_ipc847e:-:*:*:*:*:*:*:* Configuration 23 :cpe:/o:siemens:simatic_itp1000_firmware:-:*:*:*:*:*:*:* AND cpe:/h:siemens:simatic_itp1000:-:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/a:insyde:insydeh2o:5.1:*:*:*:*:*:*:* OR cpe:/a:insyde:insydeh2o:5.2:*:*:*:*:*:*:* OR cpe:/a:insyde:insydeh2o:5.3:*:*:*:*:*:*:* OR cpe:/a:insyde:insydeh2o:5.4:*:*:*:*:*:*:* Denotes that component is vulnerable BACK
insyde insydeh2o *
insyde insydeh2o *
insyde insydeh2o *
insyde insydeh2o *
insyde insydeh2o *
insyde insydeh2o *
insyde insydeh2o *
siemens ruggedcom apr1808 firmware -
siemens ruggedcom apr1808 -
siemens simatic field pg m5 firmware -
siemens simatic field pg m5 -
siemens simatic field pg m6 firmware -
siemens simatic field pg m6 -
siemens simatic ipc127e firmware -
siemens simatic ipc127e -
siemens simatic ipc227g firmware -
siemens simatic ipc227g -
siemens simatic ipc277g firmware -
siemens simatic ipc277g -
siemens simatic ipc327g firmware -
siemens simatic ipc327g -
siemens simatic ipc377g firmware -
siemens simatic ipc377g -
siemens simatic ipc427e firmware -
siemens simatic ipc427e -
siemens simatic ipc477e firmware -
siemens simatic ipc477e -
siemens simatic ipc477e pro firmware -
siemens simatic ipc477e pro -
siemens simatic ipc627e firmware -
siemens simatic ipc627e -
siemens simatic ipc647e firmware -
siemens simatic ipc647e -
siemens simatic ipc677e firmware -
siemens simatic ipc677e -
siemens simatic ipc847e firmware -
siemens simatic ipc847e -
siemens simatic itp1000 firmware -
siemens simatic itp1000 -
insyde insydeh2o 5.1
insyde insydeh2o 5.2
insyde insydeh2o 5.3
insyde insydeh2o 5.4