vulnerability
Aruba AOS-CX: CVE-2021-41839: SMM Privilege Escalation Vulnerability in NvmExpressDxe
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 5 | (AV:L/AC:L/Au:N/C:P/I:P/A:P) | Feb 1, 2022 | Feb 24, 2025 | Jul 2, 2025 |
Severity
5
CVSS
(AV:L/AC:L/Au:N/C:P/I:P/A:P)
Published
Feb 1, 2022
Added
Feb 24, 2025
Modified
Jul 2, 2025
Description
An issue was discovered in NvmExpressDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. Because of an Untrusted Pointer Dereference that causes SMM memory corruption, an attacker may be able to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM.
Solution
aruba-aos-cx-cve-2021-41839
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.