Lucene search

K
nvd[email protected]NVD:CVE-2020-5953
HistoryFeb 03, 2022 - 1:15 a.m.

CVE-2020-5953

2022-02-0301:15:07
web.nvd.nist.gov

6.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

7.5 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

20.6%

A vulnerability exists in System Management Interrupt (SWSMI) handler of InsydeH2O UEFI Firmware code located in SWSMI handler that dereferences gRT (EFI_RUNTIME_SERVICES) pointer to call a GetVariable service, which is located outside of SMRAM. This can result in code execution in SMM (escalating privilege from ring 0 to ring -2).

Affected configurations

NVD
Node
insydeinsydeh2oMatch5.12.09.0074
OR
insydeinsydeh2oMatch5.23.04.0045
OR
insydeinsydeh2oMatch5.23.45.0023
OR
insydeinsydeh2oMatch5.33.15.0034
OR
insydeinsydeh2oMatch5.34.03.0029
OR
insydeinsydeh2oMatch5.42.03.0010
Node
siemensruggedcom_ape1808Match-
AND
siemensruggedcom_ape1808_firmwareMatch-
Node
siemenssimatic_field_pg_m6Match-
AND
siemenssimatic_field_pg_m6_firmwareMatch-
Node
siemenssimatic_ipc127eMatch-
AND
siemenssimatic_ipc127e_firmwareMatch-
Node
siemenssimatic_ipc227gMatch-
AND
siemenssimatic_ipc227g_firmwareMatch-
Node
siemenssimatic_ipc277gMatch-
AND
siemenssimatic_ipc277g_firmwareMatch-
Node
siemenssimatic_itp1000Match-
AND
siemenssimatic_itp1000_firmwareMatch-
Node
siemenssimatic_ipc477e_proMatch-
AND
siemenssimatic_ipc477e_pro_firmwareMatch-
Node
siemenssimatic_ipc627eMatch-
AND
siemenssimatic_ipc627e_firmwareMatch-
Node
siemenssimatic_ipc647e_firmwareMatch-
AND
siemenssimatic_ipc647eMatch-
Node
siemenssimatic_ipc677e_firmwareMatch-
AND
siemenssimatic_ipc677eMatch-
Node
siemenssimatic_ipc847e_firmwareMatch-
AND
siemenssimatic_ipc847eMatch-
Node
siemenssimatic_ipc327g_firmwareMatch-
AND
siemenssimatic_ipc327gMatch-
Node
siemenssimatic_ipc377g_firmwareMatch-
AND
siemenssimatic_ipc377gMatch-
Node
siemenssimatic_ipc427e_firmwareMatch-
AND
siemenssimatic_ipc427eMatch-
Node
siemenssimatic_ipc477e_firmwareMatch-
AND
siemenssimatic_ipc477eMatch-
Node
siemenssimatic_field_pg_m5_firmwareMatch-
AND
siemenssimatic_field_pg_m5Match-

6.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

7.5 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

20.6%

Related for NVD:CVE-2020-5953