vulnerability

Aruba AOS-CX: CVE-2021-41839: SMM Privilege Escalation Vulnerability in NvmExpressDxe

Severity
5
CVSS
(AV:L/AC:L/Au:N/C:P/I:P/A:P)
Published
02/01/2022
Added
02/24/2025
Modified
04/03/2025

Description

An issue was discovered in NvmExpressDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. Because of an Untrusted Pointer Dereference that causes SMM memory corruption, an attacker may be able to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM.

Solution

aruba-aos-cx-cve-2021-41839
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.