Vulnerability Name: | CVE-2021-41839 (CCN-218776) | ||||||||||||
Assigned: | 2021-10-01 | ||||||||||||
Published: | 2022-02-01 | ||||||||||||
Updated: | 2022-03-29 | ||||||||||||
Summary: | An issue was discovered in NvmExpressDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. Because of an Untrusted Pointer Dereference that causes SMM memory corruption, an attacker may be able to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM. | ||||||||||||
CVSS v3 Severity: | 8.2 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H) 7.1 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C)
6.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||||||
Vulnerability Type: | CWE-476 | ||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2021-41839 Source: CONFIRM Type: Third Party Advisory https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf Source: XF Type: UNKNOWN insydeh2o-cve202141839-priv-esc(218776) Source: CONFIRM Type: Third Party Advisory https://security.netapp.com/advisory/ntap-20220217-0016/ Source: MISC Type: Vendor Advisory https://www.insyde.com/security-pledge Source: CCN Type: INSYDE-SA-2022020 Insyde Security Advisory 2022020 Source: MISC Type: Vendor Advisory https://www.insyde.com/security-pledge/SA-2022020 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Configuration 4: Configuration 5: Configuration CCN 1: ![]() | ||||||||||||
BACK |