cbcvebase.
CVE-2021-37409
published 2022-08-18

CVE-2021-37409: Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow a privileged user to potentially enable escalation of…

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow a privileged user to potentially enable escalation of privilege via local access.

Affected

15 ranges
VendorProductVersion rangeFixed in
debianfirmware-nonfree< firmware-nonfree 20220913-1 (bookworm)firmware-nonfree 20220913-1 (bookworm)
intelkiller_ac_1550_firmware< 3.1122.11053.1122.1105
intelkiller_wi-fi_6_ax1650_firmware< 3.1122.11053.1122.1105
intelkiller_wi-fi_6e_ax1675_firmware< 3.1122.11053.1122.1105
intelkiller_wi-fi_6e_ax1690_firmware< 3.1122.11053.1122.1105
intelproset_wi-fi_6e_ax210_firmware< 22.12022.120
intelwi-fi_6_ax200_firmware< 22.12022.120
intelwi-fi_6_ax201_firmware< 22.12022.120
intelwi-fi_6e_ax211_firmware< 22.12022.120
intelwi-fi_6e_ax411_firmware< 22.12022.120
intelwireless-ac_9260_firmware< 22.12022.120
intelwireless-ac_9461_firmware< 22.12022.120
intelwireless-ac_9462_firmware< 22.12022.120
intelwireless-ac_9560_firmware< 22.12022.120
intel_prosetwireless_wifi_and_killer_wifi_products

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH