CVE-2021-0071

Severity
8.8HIGH
EPSS
0.2%
top 55.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 17
Latest updateMay 24

Description

Improper input validation in firmware for some Intel(R) PROSet/Wireless WiFi in UEFI may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages13 packages

CVEListV5intel(r)_proset/wireless_wifi_in_uefiSee references
NVDintel/7265_firmware< 22.40

🔴Vulnerability Details

2
GHSA
GHSA-9mxr-w23m-77x3: Improper input validation in firmware for some Intel(R) PROSet/Wireless WiFi in UEFI may allow an unauthenticated user to potentially enable escalatio2022-05-24
CVEList
CVE-2021-0071: Improper input validation in firmware for some Intel(R) PROSet/Wireless WiFi in UEFI may allow an unauthenticated user to potentially enable escalatio2021-11-17
CVE-2021-0071 (HIGH CVSS 8.8) | Improper input validation in firmwa | cvebase.io