CVE-2021-0069
published 2021-11-17CVE-2021-0069: Improper input validation in firmware for some Intel(R) PROSet/Wireless WiFi in multiple operating systems and some Killer(TM) WiFi in Windows 10 may allow an…
PriorityP422medium6.5CVSS 3.1
AVAACLPRNUINSUCNINAH
EPSS
0.37%
29.7th percentile
Improper input validation in firmware for some Intel(R) PROSet/Wireless WiFi in multiple operating systems and some Killer(TM) WiFi in Windows 10 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| intel | 7265_firmware | < 22.40 | 22.40 |
| intel | ac1550_firmware | < 2.4.1541 | 2.4.1541 |
| intel | ac_3165_firmware | < 22.40 | 22.40 |
| intel | ac_3168_firmware | < 22.40 | 22.40 |
| intel | ac_8260_firmware | < 22.40 | 22.40 |
| intel | ac_8265_firmware | < 22.40 | 22.40 |
| intel | ac_9260_firmware | < 22.40 | 22.40 |
| intel | ac_9461_firmware | < 22.40 | 22.40 |
| intel | ac_9462_firmware | < 22.40 | 22.40 |
| intel | ac_9560_firmware | < 22.40 | 22.40 |
| intel | ax1650_firmware | < 2.4.1541 | 2.4.1541 |
| intel | ax1675_firmware | < 2.4.1541 | 2.4.1541 |
| intel | ax200_firmware | < 22.40 | 22.40 |
| intel | ax201_firmware | < 22.40 | 22.40 |
| intel | ax210_firmware | < 22.40 | 22.40 |
| intel_proset | wireless_wifi_in_multiple_operating_systems_and_some_killer_wifi_in_windows_10 | — | — |
| lettre | lettre | >= 0.7.0 < 0.9.6 | 0.9.6 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.03.3LOWAV:A/AC:L/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3gxw-m9pv-89hq: Improper input validation in firmware for some Intel(R) PROSet/Wireless WiFi in multiple operating systems and some Killer(TM) WiFi in Windows 10 may
ghsa_unreviewed·2022-05-24
CVE-2021-0069 [MEDIUM] CWE-20 GHSA-3gxw-m9pv-89hq: Improper input validation in firmware for some Intel(R) PROSet/Wireless WiFi in multiple operating systems and some Killer(TM) WiFi in Windows 10 may
Improper input validation in firmware for some Intel(R) PROSet/Wireless WiFi in multiple operating systems and some Killer(TM) WiFi in Windows 10 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
GHSA
SMTP command injection in lettre
ghsa·2021-07-12
CVE-2021-38189 [CRITICAL] CWE-147 SMTP command injection in lettre
SMTP command injection in lettre
### Impact
Affected versions of lettre allowed SMTP command injection through an attacker's controlled message body. The module for escaping lines starting with a period wouldn't catch a period that was placed after a double CRLF sequence, allowing the attacker to end the current message and write arbitrary SMTP commands after it.
### Fix
The flaw is fixed by correctly handling consecutive CRLF sequences.
### References
* [RUSTSEC-2021-0069](https://rustsec.org/advisories/RUSTSEC-2021-0069.html)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-11-17
Published