← Back to CVEs
CVE-2021-33626
HIGH7.8
Description
A vulnerability exists in SMM (System Management Mode) branch that registers a SWSMI handler that does not sufficiently check or validate the allocated buffer pointer(QWORD values for CommBuffer). This can be used by an attacker to corrupt data in SMRAM memory and even lead to arbitrary code execution.
CVE Details
CVSS v3.1 Score7.8
SeverityHIGH
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack VectorLOCAL
ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
Published10/1/2021
Last Modified11/4/2025
Sourcenvd
Honeypot Sightings0
Affected Products
insyde:insydeh2osiemens:ruggedcom_apr1808siemens:ruggedcom_apr1808_firmwaresiemens:simatic_field_pg_m5siemens:simatic_field_pg_m5_firmwaresiemens:simatic_field_pg_m6siemens:simatic_field_pg_m6_firmwaresiemens:simatic_ipc127esiemens:simatic_ipc127e_firmwaresiemens:simatic_ipc227gsiemens:simatic_ipc227g_firmwaresiemens:simatic_ipc277gsiemens:simatic_ipc277g_firmwaresiemens:simatic_ipc327gsiemens:simatic_ipc327g_firmwaresiemens:simatic_ipc377gsiemens:simatic_ipc377g_firmwaresiemens:simatic_ipc427esiemens:simatic_ipc427e_firmwaresiemens:simatic_ipc477esiemens:simatic_ipc477e_firmwaresiemens:simatic_ipc477e_prosiemens:simatic_ipc477e_pro_firmwaresiemens:simatic_ipc627esiemens:simatic_ipc627e_firmwaresiemens:simatic_ipc647esiemens:simatic_ipc647e_firmwaresiemens:simatic_ipc677esiemens:simatic_ipc677e_firmwaresiemens:simatic_ipc847esiemens:simatic_ipc847e_firmwaresiemens:simatic_itp1000siemens:simatic_itp1000_firmware
Weaknesses (CWE)
CWE-829
References
https://security.netapp.com/advisory/ntap-20220216-0006/(cve@mitre.org)
https://www.insyde.com/security-pledge(cve@mitre.org)
https://www.insyde.com/security-pledge/SA-2021001(cve@mitre.org)
https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf(af854a3a-2127-422b-91ae-364da2661108)
https://security.netapp.com/advisory/ntap-20220216-0006/(af854a3a-2127-422b-91ae-364da2661108)
https://www.insyde.com/security-pledge(af854a3a-2127-422b-91ae-364da2661108)
https://www.insyde.com/security-pledge/SA-2021001(af854a3a-2127-422b-91ae-364da2661108)
https://www.kb.cert.org/vuls/id/796611(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.