CVE-2021-41841
Status: ModifiedHigh (8.2)—
An issue was discovered in AhciBusDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. There is an SMM callout that allows an attacker to access the System Management Mode and execute arbitrary code. This occurs because of Inclusion of Functionality from an Untrusted Control Sphere.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- Base score: 8.2
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.30%
- Percentile among all scored CVEs: 21
- Score date: 10/7/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-829
References
- https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf
- https://security.netapp.com/advisory/ntap-20220217-0012/
- https://www.insyde.com/security-pledge
- https://www.insyde.com/security-pledge/SA-2022019
- https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf
- https://security.netapp.com/advisory/ntap-20220217-0012/
- https://www.insyde.com/security-pledge
- https://www.insyde.com/security-pledge/SA-2022019
- https://www.kb.cert.org/vuls/id/796611
- https://cert-portal.siemens.com/productcert/html/ssa-306654.html
Raw JSON (NVD)
Show
{
"id": "CVE-2021-41841",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.2,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 8.2,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 1.5
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
},
{
"source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
"affectedData": [
{
"vendor": "Siemens",
"product": "RUGGEDCOM APE1808 - BIOS",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V1.0.202N",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "SIMATIC Field PG M5",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V22.01.10",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "SIMATIC Field PG M6",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V26.01.13",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "SIMATIC IPC127E",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V27.01.09",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "SIMATIC IPC227G",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V28.01.04",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "SIMATIC IPC277G",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V28.01.04",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "SIMATIC IPC277G PRO",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V28.01.04",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "SIMATIC IPC327G",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V28.01.04",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "SIMATIC IPC377G",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V28.01.04",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "SIMATIC IPC427E",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V21.01.17",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "SIMATIC IPC477E",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V21.01.17",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "SIMATIC IPC477E PRO",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V21.01.17",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "SIMATIC IPC627E",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V25.02.12",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "SIMATIC IPC647E",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V25.02.12",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "SIMATIC IPC677E",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V25.02.12",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "SIMATIC IPC847E",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V25.02.12",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "SIMATIC ITP1000",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V23.01.10",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "SIPLUS IPC427E",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V21.01.17",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2022-02-03T02:15:07.207",
"references": [
{
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf",
"tags": [
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://security.netapp.com/advisory/ntap-20220217-0012/",
"tags": [
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://www.insyde.com/security-pledge",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://www.insyde.com/security-pledge/SA-2022019",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://security.netapp.com/advisory/ntap-20220217-0012/",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.insyde.com/security-pledge",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.insyde.com/security-pledge/SA-2022019",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.kb.cert.org/vuls/id/796611",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://cert-portal.siemens.com/productcert/html/ssa-306654.html",
"source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-829"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An issue was discovered in AhciBusDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. There is an SMM callout that allows an attacker to access the System Management Mode and execute arbitrary code. This occurs because of Inclusion of Functionality from an Untrusted Control Sphere."
},
{
"lang": "es",
"value": "Se ha descubierto un problema en AhciBusDxe en el kernel versión 5.0 hasta la 5.5 de InsydeH2O. Hay una llamada SMM que permite a un atacante acceder al Modo de Gestión del Sistema y ejecutar código arbitrario. Esto ocurre debido a la inclusión de funcionalidad desde una esfera de control no confiable"
}
],
"lastModified": "2026-08-11T13:17:20.860",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:insyde:insydeh2o:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "95221F93-8BE6-47E3-BFB4-E7603C320F0D",
"versionEndExcluding": "5.08.29",
"versionStartIncluding": "5.0"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:insyde:insydeh2o:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D26CDAE4-0D04-4EB2-8A8C-CDEBDF8BA38C",
"versionEndExcluding": "5.16.29",
"versionStartIncluding": "5.1"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:insyde:insydeh2o:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E0546FD8-0648-46EB-893F-411F869077E5",
"versionEndExcluding": "5.26.29",
"versionStartIncluding": "5.2"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:insyde:insydeh2o:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "89966555-5DD1-4C61-B3B2-7AF7AF7D24D9",
"versionEndExcluding": "5.35.29",
"versionStartIncluding": "5.3"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:insyde:insydeh2o:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FD4E7284-5376-4853-9C28-77867BCB1446",
"versionEndExcluding": "5.43.29",
"versionStartIncluding": "5.4"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:insyde:insydeh2o:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BE5BACC3-58DF-4CD6-A204-565CD002AC77",
"versionEndExcluding": "5.51.29",
"versionStartIncluding": "5.5"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}