CVE-2022-21151
published 2022-05-12CVE-2022-21151: Processor optimization removal or modification of security-critical code for some Intel(R) Processors may allow an authenticated user to potentially enable…
PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.35%
27.2th percentile
Processor optimization removal or modification of security-critical code for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | intel-microcode | < intel-microcode 3.20220510.1 (bookworm) | intel-microcode 3.20220510.1 (bookworm) |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Intel Microcode vulnerabilities
osv·2022-07-28·CVSS 5.5
CVE-2021-0145 [MEDIUM] Intel Microcode vulnerabilities
Intel Microcode vulnerabilities
Joseph Nuzman discovered that some Intel processors did not properly
initialise shared resources. A local attacker could use this to obtain
sensitive information. (CVE-2021-0145)
Mark Ermolov, Dmitry Sklyarov and Maxim Goryachy discovered that some Intel
processors did not prevent test and debug logic from being activated at
runtime. A local attacker could use this to escalate
privileges. (CVE-2021-0146)
It was discovered that some Intel processors did not implement sufficient
control flow management. A local attacker could use this to cause a denial
of service (system crash). (CVE-2021-0127)
It was discovered that some Intel processors did not completely perform
cleanup actions on multi-core shared buffers. A local attacker could
possibly use this to ex
OSV
intel-microcode vulnerabilities
osv·2022-06-20·CVSS 5.5
CVE-2021-0127 [MEDIUM] intel-microcode vulnerabilities
intel-microcode vulnerabilities
It was discovered that some Intel processors did not implement sufficient
control flow management. A local attacker could use this to cause a denial
of service. (CVE-2021-0127)
Joseph Nuzman discovered that some Intel processors did not properly
initialise shared resources. A local attacker could use this to obtain
sensitive information. (CVE-2021-0145)
Mark Ermolov, Dmitry Sklyarov and Maxim Goryachy discovered that some Intel
processors did not prevent test and debug logic from being activated at
runtime. A local attacker could use this to escalate
privileges. (CVE-2021-0146)
It was discovered that some Intel processors did not properly restrict
access in some situations. A local attacker could use this to obtain
sensitive information. (CVE-2021-33117)
GHSA
GHSA-f82m-qq46-pcww: Processor optimization removal or modification of security-critical code for some Intel(R) Processors may allow an authenticated user to potentially e
ghsa_unreviewed·2022-05-13
CVE-2022-21151 [MEDIUM] GHSA-f82m-qq46-pcww: Processor optimization removal or modification of security-critical code for some Intel(R) Processors may allow an authenticated user to potentially e
Processor optimization removal or modification of security-critical code for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
OSV
CVE-2022-21151: Processor optimization removal or modification of security-critical code for some Intel(R) Processors may allow an authenticated user to potentially e
osv·2022-05-12·CVSS 5.5
CVE-2022-21151 [MEDIUM] CVE-2022-21151: Processor optimization removal or modification of security-critical code for some Intel(R) Processors may allow an authenticated user to potentially e
Processor optimization removal or modification of security-critical code for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
CISA ICS
Mitsubishi Electric FA Engineering Software Products
cisa_ics·2023-12-07·CVSS 5.5
[MEDIUM] Mitsubishi Electric FA Engineering Software Products
ICS Advisory
##
Mitsubishi Electric FA Engineering Software Products
Release DateDecember 07, 2023
Alert CodeICSA-23-341-01
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 5.3
- Vendor: Mitsubishi Electric
- Equipment: MELIPC , MELSEC iQ-R, and MELSEC Q Series
- Vulnerabilities: Processor Optimization Removal or Modification of Security-Critical Code, Observable Discrepancy
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow a malicious attacker to disclose information in the affected products.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Mitsubishi Electric reports the following versions of FA Engineering Software Products are affected. For the correspondence table of the affected products and each vulnerability, refer to
Ubuntu
Intel Microcode vulnerabilities
vendor_ubuntu·2022-07-28·CVSS 5.5
CVE-2021-0145 [MEDIUM] Intel Microcode vulnerabilities
Title: Intel Microcode vulnerabilities
Summary: Several security issues were fixed in Intel Microcode.
Joseph Nuzman discovered that some Intel processors did not properly
initialise shared resources. A local attacker could use this to obtain
sensitive information. (CVE-2021-0145)
Mark Ermolov, Dmitry Sklyarov and Maxim Goryachy discovered that some Intel
processors did not prevent test and debug logic from being activated at
runtime. A local attacker could use this to escalate
privileges. (CVE-2021-0146)
It was discovered that some Intel processors did not implement sufficient
control flow management. A local attacker could use this to cause a denial
of service (system crash). (CVE-2021-0127)
It was discovered that some Intel processors did not completely perform
cleanup actions on m
Ubuntu
Intel Microcode vulnerabilities
vendor_ubuntu·2022-06-20·CVSS 5.5
CVE-2021-0127 [MEDIUM] Intel Microcode vulnerabilities
Title: Intel Microcode vulnerabilities
Summary: Several security issues were fixed in Intel Microcode.
It was discovered that some Intel processors did not implement sufficient
control flow management. A local attacker could use this to cause a denial
of service. (CVE-2021-0127)
Joseph Nuzman discovered that some Intel processors did not properly
initialise shared resources. A local attacker could use this to obtain
sensitive information. (CVE-2021-0145)
Mark Ermolov, Dmitry Sklyarov and Maxim Goryachy discovered that some Intel
processors did not prevent test and debug logic from being activated at
runtime. A local attacker could use this to escalate
privileges. (CVE-2021-0146)
It was discovered that some Intel processors did not properly restrict
access in some situations. A local a
Red Hat
hw: cpu: information disclosure in certain Intel processors
vendor_redhat·2022-05-10·CVSS 5.5
CVE-2022-21151 [MEDIUM] CWE-212 hw: cpu: information disclosure in certain Intel processors
hw: cpu: information disclosure in certain Intel processors
Processor optimization removal or modification of security-critical code for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
A flaw was found in hw. Processor optimization removal or modification of security-critical code for some Intel(R) processors may potentially allow an authenticated user to enable information disclosure via local access.
Statement: Red Hat has very limited to no visibility and control over binary blobs provided by third-party vendors. Red Hat relies heavily on the vendors to provide timely updates and information about included changes for this content and in most cases merely acts as a release vehicle between the third-party vendor a
Debian
CVE-2022-21151: intel-microcode - Processor optimization removal or modification of security-critical code for som...
vendor_debian·2022·CVSS 5.5
CVE-2022-21151 [MEDIUM] CVE-2022-21151: intel-microcode - Processor optimization removal or modification of security-critical code for som...
Processor optimization removal or modification of security-critical code for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 3.20220510.1)
bullseye: resolved (fixed in 3.20220510.1~deb11u1)
forky: resolved (fixed in 3.20220510.1)
sid: resolved (fixed in 3.20220510.1)
trixie: resolved (fixed in 3.20220510.1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://security.netapp.com/advisory/ntap-20220826-0003/https://www.debian.org/security/2022/dsa-5178https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00617.htmlhttps://security.netapp.com/advisory/ntap-20220826-0003/https://www.debian.org/security/2022/dsa-5178https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00617.html
2022-05-12
Published