CVE-2021-0144
published 2021-07-14CVE-2021-0144: Insecure default variable initialization for the Intel BSSA DFT feature may allow a privileged user to potentially enable an escalation of privilege via local…
PriorityP425medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.33%
24.9th percentile
Insecure default variable initialization for the Intel BSSA DFT feature may allow a privileged user to potentially enable an escalation of privilege via local access.
Affected
252 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| intel | core_i5 | — | — |
| intel | core_i5 | — | — |
| intel | core_i5 | — | — |
| intel | core_i5 | — | — |
| intel | core_i5 | — | — |
| intel | core_i5 | — | — |
| intel | core_i5 | — | — |
| intel | core_i5 | — | — |
| intel | core_i5 | — | — |
| intel | core_i5 | — | — |
| intel | core_i5 | — | — |
| intel | core_i5 | — | — |
| intel | core_i5 | — | — |
| intel | core_i5 | — | — |
| intel | core_i5 | — | — |
| intel | core_i5 | — | — |
| intel | core_i5 | — | — |
| intel | core_i5 | — | — |
| intel | core_i5 | — | — |
| intel | core_i5 | — | — |
| intel | core_i5 | — | — |
| intel | core_i5 | — | — |
| intel | core_i5 | — | — |
| intel | core_i5 | — | — |
| intel | core_i5 | — | — |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat6.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: hw: Insecure default variable initialization for the Intel BSSA DFT feature
vendor_redhat·2021-07-13·CVSS 6.7
CVE-2021-0144 [MEDIUM] CWE-1188 kernel: hw: Insecure default variable initialization for the Intel BSSA DFT feature
kernel: hw: Insecure default variable initialization for the Intel BSSA DFT feature
Insecure default variable initialization for the Intel BSSA DFT feature may allow a privileged user to potentially enable an escalation of privilege via local access.
A flaw was found in the Linux kernel. The Intel BIOS Shared SW Architecture (BSSA) Design for Test (DFT) feature may allow escalation of privilege in the customer build time configuration. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Statement: This issue is not in Red Hat supported software. Please contact your system manufacturer for more information and/or potential BIOS firmware update that addresses this issue.
Package: kernel (Red Hat Enterprise Linux 6) - Not aff
GHSA
GHSA-q9f9-4gv4-x42q: Insecure default variable initialization for the Intel BSSA DFT feature may allow a privileged user to potentially enable an escalation of privilege v
ghsa_unreviewed·2022-05-24
CVE-2021-0144 [MEDIUM] CWE-1188 GHSA-q9f9-4gv4-x42q: Insecure default variable initialization for the Intel BSSA DFT feature may allow a privileged user to potentially enable an escalation of privilege v
Insecure default variable initialization for the Intel BSSA DFT feature may allow a privileged user to potentially enable an escalation of privilege via local access.
No detection rules found.
No public exploits indexed.
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00525.htmlhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00527.htmlhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00525.htmlhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00527.html
2021-07-14
Published