CVE-2021-42060
Summary
| CVE | CVE-2021-42060 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-02-03 02:15:07 UTC |
| Updated | 2026-08-11 13:17:21 UTC |
| Description | An issue was discovered in Insyde InsydeH2O Kernel 5.0 through 05.08.41, Kernel 5.1 through 05.16.41, Kernel 5.2 before 05.23.22, and Kernel 5.3 before 05.32.22. An Int15ServiceSmm SMM callout vulnerability allows an attacker to hijack execution flow of code running in System Management Mode. Exploiting this issue could lead to escalating privileges to SMM. |
Risk And Classification
Primary CVSS: v3.1 8.2 HIGH from [email protected]
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Problem Types: NVD-CWE-noinfo | n/a
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 8.2 | HIGH | CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 7.2 | AV:L/AC:L/Au:N/C:C/I:C/A:C |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
HighUser Interaction
NoneScope
ChangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Na | N/a | affected n/a | Not specified |
| ADP | Siemens | RUGGEDCOM APE1808 - BIOS | affected V1.0.202N custom | Not specified |
| ADP | Siemens | SIMATIC Field PG M5 | affected V22.01.10 custom | Not specified |
| ADP | Siemens | SIMATIC Field PG M6 | affected V26.01.13 custom | Not specified |
| ADP | Siemens | SIMATIC IPC127E | affected V27.01.09 custom | Not specified |
| ADP | Siemens | SIMATIC IPC227G | affected V28.01.04 custom | Not specified |
| ADP | Siemens | SIMATIC IPC277G | affected V28.01.04 custom | Not specified |
| ADP | Siemens | SIMATICIPC277G PRO | affected V28.01.04 custom | Not specified |
| ADP | Siemens | SIMATIC IPC327G | affected V28.01.04 custom | Not specified |
| ADP | Siemens | SIMATIC IPC377G | affected V28.01.04 custom | Not specified |
| ADP | Siemens | SIMATIC IPC427E | affected V21.01.17 custom | Not specified |
| ADP | Siemens | SIMATIC IPC477E | affected V21.01.17 custom | Not specified |
| ADP | Siemens | SIMATIC IPC477E PRO | affected V21.01.17 custom | Not specified |
| ADP | Siemens | SIMATIC IPC627E | affected V25.02.12 custom | Not specified |
| ADP | Siemens | SIMATIC IPC647E | affected V25.02.12 custom | Not specified |
| ADP | Siemens | SIMATIC IPC677E | affected V25.02.12 custom | Not specified |
| ADP | Siemens | SIMATIC IPC847E | affected V25.02.12 custom | Not specified |
| ADP | Siemens | SIMATIC ITP1000 | affected V23.01.10 custom | Not specified |
| ADP | Siemens | SIPLUS IPC427E | affected V21.01.17 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| cert-portal.siemens.com/productcert/html/ssa-306654.html | 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e | cert-portal.siemens.com | |
| CVE-2021-42060 InsydeH20 Vulnerability in NetApp Products | NetApp Product Security | af854a3a-2127-422b-91ae-364da2661108 | security.netapp.com | Third Party Advisory |
| Insyde Security Advisory 2022007 | Insyde Software | af854a3a-2127-422b-91ae-364da2661108 | www.insyde.com | Vendor Advisory |
| Insyde's Security Pledge | Insyde Software | af854a3a-2127-422b-91ae-364da2661108 | www.insyde.com | Vendor Advisory |
| www.kb.cert.org/vuls/id/796611 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | |
| cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf | af854a3a-2127-422b-91ae-364da2661108 | cert-portal.siemens.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 590981 Siemens Industrial Products Insyde BIOS Multiple Vulnerabilities (SSA-306654)