An issue was discovered in Insyde InsydeH2O with Kernel 5.0 before 05.08.42, Kernel 5.1 before 05.16.42, Kernel 5.2 before 05.26.42, Kernel 5.3 before 05.35.42, Kernel 5.4 before 05.42.51, and Kernel 5.5 before 05.50.51. An SMM memory corruption vulnerability in FvbServicesRuntimeDxe allows a possible attacker to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM.

Project Subscriptions

Vendors Products
Insydeh2o Subscribe
Siemens Subscribe
Ruggedcom Ape1808 Subscribe
Ruggedcom Ape1808 Firmware Subscribe
Simatic Field Pg M5 Subscribe
Simatic Field Pg M5 Firmware Subscribe
Simatic Field Pg M6 Subscribe
Simatic Field Pg M6 Firmware Subscribe
Simatic Ipc127e Subscribe
Simatic Ipc127e Firmware Subscribe
Simatic Ipc227g Subscribe
Simatic Ipc227g Firmware Subscribe
Simatic Ipc277g Subscribe
Simatic Ipc277g Firmware Subscribe
Simatic Ipc327g Subscribe
Simatic Ipc327g Firmware Subscribe
Simatic Ipc377g Subscribe
Simatic Ipc377g Firmware Subscribe
Simatic Ipc427e Subscribe
Simatic Ipc427e Firmware Subscribe
Simatic Ipc477e Subscribe
Simatic Ipc477e Firmware Subscribe
Simatic Ipc627e Subscribe
Simatic Ipc627e Firmware Subscribe
Simatic Ipc647e Subscribe
Simatic Ipc647e Firmware Subscribe
Simatic Ipc677e Subscribe
Simatic Ipc677e Firmware Subscribe
Simatic Ipc847e Subscribe
Simatic Ipc847e Firmware Subscribe
Simatic Itp1000 Subscribe
Simatic Itp1000 Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2021-29522 An issue was discovered in Insyde InsydeH2O with Kernel 5.0 before 05.08.42, Kernel 5.1 before 05.16.42, Kernel 5.2 before 05.26.42, Kernel 5.3 before 05.35.42, Kernel 5.4 before 05.42.51, and Kernel 5.5 before 05.50.51. An SMM memory corruption vulnerability in FvbServicesRuntimeDxe allows a possible attacker to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 04 Nov 2025 20:30:00 +0000

Type Values Removed Values Added
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-11-04T19:12:43.116Z

Reserved: 2021-10-18T00:00:00.000Z

Link: CVE-2021-42554

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-02-03T02:15:07.380

Modified: 2025-11-04T20:16:02.097

Link: CVE-2021-42554

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses