Lucene search

K
nvd[email protected]NVD:CVE-2021-42059
HistoryFeb 03, 2022 - 2:15 a.m.

CVE-2021-42059

2022-02-0302:15:07
CWE-787
web.nvd.nist.gov
1

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

6.7 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

26.7%

An issue was discovered in Insyde InsydeH2O Kernel 5.0 before 05.08.41, Kernel 5.1 before 05.16.41, Kernel 5.2 before 05.26.41, Kernel 5.3 before 05.35.41, and Kernel 5.4 before 05.42.20. A stack-based buffer overflow leads toarbitrary code execution in UEFI DisplayTypeDxe DXE driver.

Affected configurations

NVD
Node
insydeinsydeh2oRange5.05.08.41
Node
insydeinsydeh2oRange5.15.16.41
Node
insydeinsydeh2oRange5.25.26.41
Node
insydeinsydeh2oRange5.35.35.41
Node
insydeinsydeh2oRange5.45.42.20
Node
siemenssimatic_field_pg_m5Match-
AND
siemenssimatic_field_pg_m5_firmware
Node
siemenssimatic_field_pg_m6Match-
AND
siemenssimatic_field_pg_m6_firmware
Node
siemenssimatic_ipc127eMatch-
AND
siemenssimatic_ipc127e_firmware
Node
siemenssimatic_ipc227gMatch-
AND
siemenssimatic_ipc227g_firmware
Node
siemenssimatic_ipc277gMatch-
AND
siemenssimatic_ipc277g_firmware
Node
siemenssimatic_ipc327gMatch-
AND
siemenssimatic_ipc327g_firmware
Node
siemenssimatic_ipc377g_firmware
AND
siemenssimatic_ipc377gMatch-
Node
siemenssimatic_ipc427e_firmware
AND
siemenssimatic_ipc427eMatch-
Node
siemenssimatic_ipc477e_firmware
AND
siemenssimatic_ipc477eMatch-
Node
siemenssimatic_ipc627e_firmware
AND
siemenssimatic_ipc627eMatch-
Node
siemenssimatic_ipc647e_firmware
AND
siemenssimatic_ipc647eMatch-
Node
siemenssimatic_ipc677e_firmware
AND
siemenssimatic_ipc677eMatch-
Node
siemenssimatic_ipc847e_firmware
AND
siemenssimatic_ipc847eMatch-
Node
siemenssimatic_itp1000_firmware
AND
siemenssimatic_itp1000Match-

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

6.7 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

26.7%

Related for NVD:CVE-2021-42059