6.7Medium
Insyde Insydeh2o
CVE-2020-27339
In the kernel in Insyde InsydeH2O 5.x, certain SMM drivers did not correctly validate the CommBuffer and CommBufferSize parameters, allowing callers to corrupt either the firmware or the OS memory. The fixed versions for this issue in the AhciBusDxe, IdeBusDxe, NvmExpressDxe, SdHostDriverDxe, and SdMmcDeviceDxe drivers are 05.16.25, 05.26.25, 05.35.25, 05.43.25, and 05.51.25 (for Kernel 5.1 through 5.5).
What this means for your business
- It affects Insydeh2o. It matters if your company, or a supplier that handles your data, runs it.
- An attacker can use it only with access to the machine itself, with an administrator login, and without anyone at your company clicking anything.
What to do
- 1Check whether your company or your suppliers run Insydeh2o, and which version. The affected versions are listed further down this page.
- 2If you do, apply the vendor's fix. A patch or vendor advisory has been published.
Not sure if your company is exposed?
Fastnexa’s certified penetration testers can check whether attackers could use this flaw, or others like it, against your websites, apps and network. The full test is free for our first 10 founding clients until 31 December 2026.
Scoring
- CVSS
- 6.7 (v3.1)
- Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H- Weakness
- CWE-20
- Assigned by
- cve@mitre.org
Dates
- Published
- 2021-06-16
- Last modified
- 2026-08-11
- Sources
- NVD
Affected products
- Insyde Insydeh2o5.3 - 5.34.44, 5.2 - 5.25.44, 5.1 - 5.16.25, 5.4 - 5.42.44, 5.3 - 5.35.25, 5.2 - 5.26.25, 5.4 - 5.43.25
- Siemens Ruggedcom Apr1808 Firmwareall versions
- Siemens Ruggedcom Apr1808all versions
- Siemens Simatic Field Pg M5 Firmwareall versions
- Siemens Simatic Field Pg M5all versions
- Siemens Simatic Field Pg M6 Firmwareall versions
- Siemens Simatic Field Pg M6all versions
- Siemens Simatic Ipc127e Firmwareall versions
- Siemens Simatic Ipc127eall versions
- Siemens Simatic Ipc227g Firmwareall versions
- Siemens Simatic Ipc227gall versions
- Siemens Simatic Ipc277g Firmwareall versions
As listed in the NVD configuration data. Not a statement about your estate.
References
- https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf
- https://security.netapp.com/advisory/ntap-20220216-0005/
- https://www.insyde.com/security-pledge/SA-2021001
- https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf
- https://security.netapp.com/advisory/ntap-20220216-0005/
- https://www.insyde.com/security-pledge/SA-2021001
- https://www.kb.cert.org/vuls/id/796611
- https://cert-portal.siemens.com/productcert/html/ssa-306654.html