CVE-2022-21233
published 2022-08-18CVE-2022-21233: Improper isolation of shared resources in some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.33%
25.4th percentile
Improper isolation of shared resources in some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | intel-microcode | < intel-microcode 3.20220809.1 (bookworm) | intel-microcode 3.20220809.1 (bookworm) |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2022-21233: Improper isolation of shared resources in some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local
osv·2022-08-18·CVSS 5.5
CVE-2022-21233 [MEDIUM] CVE-2022-21233: Improper isolation of shared resources in some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local
Improper isolation of shared resources in some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
CISA ICS
Siemens SIMATIC S7-1500 TM MFP BIOS
cisa_ics·2023-06-15·CVSS 5.9
[MEDIUM] Siemens SIMATIC S7-1500 TM MFP BIOS
ICS Advisory
##
Siemens SIMATIC S7-1500 TM MFP BIOS
Release DateJune 15, 2023
Alert CodeICSA-23-166-10
## As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely / low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 TM MFP
- Vulnerabilities: Improper Input Validation, Out-of-bounds Read, Use After Free, Out-of-bounds Write, Infinite Loop, Reachable Assertion, Off-by-one Error, Incorrect Default Permissions, Double Fr
Ubuntu
Intel Microcode vulnerability
vendor_ubuntu·2022-09-15
CVE-2022-21233 Intel Microcode vulnerability
Title: Intel Microcode vulnerability
Summary: A security issue was fixed in Intel Microcode.
Pietro Borrello, Andreas Kogler, Martin Schwarzl, Daniel Gruss, Michael
Schwarz and Moritz Lipp discovered that some Intel processors did not
properly clear data between subsequent xAPIC MMIO reads. This could allow a
local attacker to compromise SGX enclaves.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
hw: cpu: Intel: Stale Data Read from legacy xAPIC vulnerability
vendor_redhat·2022-08-09·CVSS 5.5
CVE-2022-21233 [MEDIUM] CWE-200 hw: cpu: Intel: Stale Data Read from legacy xAPIC vulnerability
hw: cpu: Intel: Stale Data Read from legacy xAPIC vulnerability
Improper isolation of shared resources in some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
A flaw was found in hw. The APIC can operate in xAPIC mode (also known as a legacy mode), in which APIC configuration registers are exposed through a memory-mapped I/O (MMIO) page. This flaw allows an attacker who can execute code on a target CPU to query the APIC configuration page. When reading the APIC configuration page with an unaligned read from the MMIO page, the registers may return stale data from previous requests made by the same processor core to the same configuration page, leading to unauthorized access.
Statement: Red Hat has very limited to no visibilit
Debian
CVE-2022-21233: intel-microcode - Improper isolation of shared resources in some Intel(R) Processors may allow a p...
vendor_debian·2022·CVSS 5.5
CVE-2022-21233 [MEDIUM] CVE-2022-21233: intel-microcode - Improper isolation of shared resources in some Intel(R) Processors may allow a p...
Improper isolation of shared resources in some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 3.20220809.1)
bullseye: resolved (fixed in 3.20230214.1~deb11u1)
forky: resolved (fixed in 3.20220809.1)
sid: resolved (fixed in 3.20220809.1)
trixie: resolved (fixed in 3.20220809.1)
No detection rules found.
No public exploits indexed.
https://lists.debian.org/debian-lts-announce/2023/04/msg00000.htmlhttps://security.netapp.com/advisory/ntap-20220923-0002/https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00657.htmlhttps://lists.debian.org/debian-lts-announce/2023/04/msg00000.htmlhttps://security.netapp.com/advisory/ntap-20220923-0002/https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00657.html
2022-08-18
Published