The vendor explicitly identifies these products as affected by this CVE.
- RUGGEDCOM APE1808 - BIOS < V1.0.202N
- SIMATIC Field PG M5 < V22.01.10
- SIMATIC Field PG M6 < V26.01.13
- SIMATIC IPC127E < V27.01.09
- SIMATIC IPC227G < V28.01.04
- SIMATIC IPC277G < V28.01.04
- SIMATIC IPC277G PRO < V28.01.04
- SIMATIC IPC327G < V28.01.04
- SIMATIC IPC377G < V28.01.04
- SIMATIC IPC427E < V21.01.17
- SIMATIC IPC477E < V21.01.17
- SIMATIC IPC477E PRO < V21.01.17
- Summary
- An issue was discovered in SdHostDriver in Insyde InsydeH2O with kernel 5.1 before 05.16.25, 5.2 before 05.26.25, 5.3 before 05.35.25, 5.4 before 05.43.25, and 5.5 before 05.51.25. A vulnerability exists in the SMM (System Management Mode) branch that registers a SWSMI handler that does not sufficiently check or validate the allocated buffer pointer (CommBufferData).
- Remediation
- Update to V1.0.202N or later version
