CVE-2020-5953

moderate-risk
Published 2022-02-03

A vulnerability exists in System Management Interrupt (SWSMI) handler of InsydeH2O UEFI Firmware code located in SWSMI handler that dereferences gRT (EFI_RUNTIME_SERVICES) pointer to call a GetVariable service, which is located outside of SMRAM. This can result in code execution in SMM (escalating privilege from ring 0 to ring -2).

Do I need to act?

-
0.07% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.5/10 High
LOCAL / HIGH complexity

Affected Products (20)

Ruggedcom Ape1808 Firmware
Simatic Field Pg M6 Firmware
Simatic Ipc127E Firmware
Simatic Ipc227G Firmware
Simatic Ipc277G Firmware
Simatic Ipc477E Pro Firmware
Simatic Ipc627E Firmware
Simatic Ipc647E Firmware
Simatic Ipc677E Firmware
Simatic Ipc847E Firmware
Simatic Ipc327G Firmware
Simatic Ipc377G Firmware

Affected Vendors

40
/ 100
moderate-risk
Severity 20/34 · Moderate
Exploitability 0/34 · Minimal
Exposure 20/34 · Moderate