← Back

CVE-2021-42554

nvd nist
Published: Feb 3, 2022Modified: Jun 17, 2026

JSON object

Loading...
8.2
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Exploitability: 1.5 / Impact: 6.0
Source: NVD

Description

An issue was discovered in Insyde InsydeH2O with Kernel 5.0 before 05.08.42, Kernel 5.1 before 05.16.42, Kernel 5.2 before 05.26.42, Kernel 5.3 before 05.35.42, Kernel 5.4 before 05.42.51, and Kernel 5.5 before 05.50.51. An SMM memory corruption vulnerability in FvbServicesRuntimeDxe allows a possible attacker to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM.

Affected (21)

1 product
Insydeh2o
15 products
Simatic Field Pg M5 Firmware
Simatic Field Pg M6 Firmware
Simatic Ipc127e Firmware
Simatic Ipc227g Firmware
Simatic Ipc277g Firmware
Simatic Ipc327g Firmware
Simatic Ipc377g Firmware
Simatic Ipc427e Firmware
Simatic Ipc477e Firmware
Simatic Ipc627e Firmware
Simatic Ipc647e Firmware
Simatic Ipc677e Firmware
Simatic Ipc847e Firmware
Simatic Itp1000 Firmware
Ruggedcom Ape1808 Firmware
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 5.0 to 5.08.42
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
From 5.1 to 5.16.42
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
From 5.2 to 5.26.42
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
From 5.3 to 5.35.42
Configuration E
1 vulnerable
Vulnerable SoftwareAffected Versions
From 5.4 to 5.42.51
Configuration F
1 vulnerable
Vulnerable SoftwareAffected Versions
From 5.5 to 5.50.51
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Siemens
Simatic Field Pg M5
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Siemens
Simatic Field Pg M6
All versions
Configuration I
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Siemens
Simatic Ipc127e
All versions
Configuration J
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Siemens
Simatic Ipc227g
All versions
Configuration K
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Siemens
Simatic Ipc277g
All versions
Configuration L
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Siemens
Simatic Ipc327g
All versions
Configuration M
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Siemens
Simatic Ipc377g
All versions
Configuration N
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Siemens
Simatic Ipc427e
All versions
Configuration O
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Siemens
Simatic Ipc477e
All versions
Configuration P
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Siemens
Simatic Ipc627e
All versions
Configuration Q
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Siemens
Simatic Ipc647e
All versions
Configuration R
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Siemens
Simatic Ipc677e
All versions
Configuration S
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Siemens
Simatic Ipc847e
All versions
Configuration T
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Siemens
Simatic Itp1000
All versions
Configuration U
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Siemens
Ruggedcom Ape1808
All versions

References (9)

Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.