CVE-2021-33162
8.4
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
Exploitability: 2.0 / Impact: 5.8
Source: secure@intel.com (Secondary)
Description
Improper access control in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow an authenticated user to potentially enable escalation of privilege via local access.
Affected (4)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.87 |
| Running on/with | Platform Versions |
|---|---|
Intel Ethernet Controller I225 It | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.87 |
| Running on/with | Platform Versions |
|---|---|
Intel Ethernet Controller I225 Lm | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.87 |
| Running on/with | Platform Versions |
|---|---|
Intel Ethernet Controller I225 V | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 29.0.1 |
References (2)
Source: secure@intel.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.