vulnerability
Aruba AOS-CX: CVE-2021-41839: SMM Privilege Escalation Vulnerability in NvmExpressDxe
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
5 | (AV:L/AC:L/Au:N/C:P/I:P/A:P) | 02/01/2022 | 02/24/2025 | 04/03/2025 |
Severity
5
CVSS
(AV:L/AC:L/Au:N/C:P/I:P/A:P)
Published
02/01/2022
Added
02/24/2025
Modified
04/03/2025
Description
An issue was discovered in NvmExpressDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. Because of an Untrusted Pointer Dereference that causes SMM memory corruption, an attacker may be able to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM.
Solution
aruba-aos-cx-cve-2021-41839

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.