CVE-2021-33117Improper Removal of Sensitive Information Before Storage or Transfer in Intel Bios

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 66.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 12
Latest updateJul 28

Description

Improper access control for some 3rd Generation Intel(R) Xeon(R) Scalable Processors before BIOS version MR7, may allow a local attacker to potentially enable information disclosure via local access.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

NVDintel/bios< mr7
debiandebian/intel-microcode< intel-microcode 3.20220207.1 (bookworm)

🔴Vulnerability Details

4
OSV
Intel Microcode vulnerabilities2022-07-28
OSV
intel-microcode vulnerabilities2022-06-20
GHSA
GHSA-fmf3-xj8j-qrw9: Improper access control for some 3rd Generation Intel(R) Xeon(R) Scalable Processors before BIOS version MR7, may allow a local attacker to potentiall2022-05-13
OSV
CVE-2021-33117: Improper access control for some 3rd Generation Intel(R) Xeon(R) Scalable Processors before BIOS version MR7, may allow a local attacker to potentiall2022-05-12

📋Vendor Advisories

4
Ubuntu
Intel Microcode vulnerabilities2022-07-28
Ubuntu
Intel Microcode vulnerabilities2022-06-20
Red Hat
hw: cpu: information disclosure in Intel® Xeon® Scalable Processors2022-05-10
Debian
CVE-2021-33117: intel-microcode - Improper access control for some 3rd Generation Intel(R) Xeon(R) Scalable Proces...2021