← Vulnerability feed

Vulnerability record · CVE-2020-5953 · published 3 February 2022

CVE-2020-5953: Insydeh2o vulnerability

Insyde · Insydeh2o

A vulnerability exists in System Management Interrupt (SWSMI) handler of InsydeH2O UEFI Firmware code located in SWSMI handler that dereferences gRT (EFI_RUNTIME_SERVICES) pointer to call a GetVariable service, which is located outside of SMRAM. This can result in code execution in SMM (escalating privilege from ring 0 to ring -2).

7.5 CVSS 3.1 High EPSS 0.28% · top 81.0%
7.5CVSS 3.1 base score, v2 6.9
0.28%EPSS exploitation probability, 30 days
NoNot in CISA KEV
17Affected product versions listed by NVD
10References
11 Aug 2026Last modified by NVD

Description

A vulnerability exists in System Management Interrupt (SWSMI) handler of InsydeH2O UEFI Firmware code located in SWSMI handler that dereferences gRT (EFI_RUNTIME_SERVICES) pointer to call a GetVariable service, which is located outside of SMRAM. This can result in code execution in SMM (escalating privilege from ring 0 to ring -2).

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

Affected products

17 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-5953 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-24858Fortinet FortiCloud SSO authentication bypass across registered devicesA CWE-288 authentication bypass in Fortinet FortiAnalyzer, FortiManager, FortiNAC-F, FortiOS, FortiProxy and FortiWeb lets an attacker with a FortiCl…KEVEPSS 86%analysed9.8CVE-2025-25249Fortinet FortiOS and FortiSwitchManager heap buffer overflow via crafted packetsA heap-based buffer overflow (CWE-122/CWE-787) in Fortinet FortiOS 6.4 through 7.6.3 and FortiSwitchManager 7.0 through 7.2.6 lets an unauthenticated…KEVEPSS 3.9%analysed9.8CVE-2025-59718Fortinet FortiOS/FortiProxy SAML signature check bypass in FortiCloud SSOFortiOS, FortiProxy and FortiSwitchManager fail to properly verify the cryptographic signature of SAML responses used for FortiCloud SSO login. An un…KEVEPSS 68%analysed9.8CVE-2017-5689Intel AMT, ISM and SBT improper privilege management allows privilege escalationIntel manageability SKUs (AMT, ISM, SBT) contain an improper privilege management flaw. An unprivileged network attacker can gain system privileges o…KEVEPSS 92%analysed9.3CVE-2026-0300PAN-OS User-ID Authentication Portal buffer overflow allows root code executionA buffer overflow (out-of-bounds write, CWE-787) in the User-ID Authentication Portal (Captive Portal) service of Palo Alto Networks PAN-OS lets an u…KEVEPSS 32%analysed7.8CVE-2026-0257PAN-OS GlobalProtect authentication bypass via unvalidated cookiesPAN-OS GlobalProtect portal and gateway contain authentication bypass flaws that let an attacker skip security restrictions and establish an unauthor…KEVEPSS 96%analysed7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed9.8CVE-2023-39281Insydeh2o out-of-bounds write vulnerabilityA stack buffer overflow vulnerability discovered in AsfSecureBootDxe in Insyde InsydeH2O with kernel 5.0 through 5.5 allows attackers to run arbitrar…EPSS 0.49%

Source: NIST National Vulnerability Database (record CVE-2020-5953), CISA KEV, FIRST EPSS (scores of 2026-10-05). This page is refreshed as NVD updates the record.