CVE-2020-5953
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
03/02/2022
Last modified:
04/11/2025
Description
A vulnerability exists in System Management Interrupt (SWSMI) handler of InsydeH2O UEFI Firmware code located in SWSMI handler that dereferences gRT (EFI_RUNTIME_SERVICES) pointer to call a GetVariable service, which is located outside of SMRAM. This can result in code execution in SMM (escalating privilege from ring 0 to ring -2).
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
6.90
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:insyde:insydeh2o:5.12.09.0074:*:*:*:*:*:*:* | ||
| cpe:2.3:a:insyde:insydeh2o:5.23.04.0045:*:*:*:*:*:*:* | ||
| cpe:2.3:a:insyde:insydeh2o:5.23.45.0023:*:*:*:*:*:*:* | ||
| cpe:2.3:a:insyde:insydeh2o:5.33.15.0034:*:*:*:*:*:*:* | ||
| cpe:2.3:a:insyde:insydeh2o:5.34.03.0029:*:*:*:*:*:*:* | ||
| cpe:2.3:a:insyde:insydeh2o:5.42.03.0010:*:*:*:*:*:*:* | ||
| cpe:2.3:o:siemens:ruggedcom_ape1808_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:siemens:ruggedcom_ape1808:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:siemens:simatic_field_pg_m6_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:siemens:simatic_field_pg_m6:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:siemens:simatic_ipc127e_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:siemens:simatic_ipc127e:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:siemens:simatic_ipc227g_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:siemens:simatic_ipc227g:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:siemens:simatic_ipc277g_firmware:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf
- https://security.netapp.com/advisory/ntap-20220222-0005/
- https://www.insyde.com/products
- https://www.insyde.com/security-pledge
- https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf
- https://security.netapp.com/advisory/ntap-20220222-0005/
- https://www.insyde.com/products
- https://www.insyde.com/security-pledge
- https://www.kb.cert.org/vuls/id/796611



