CVE-2021-33107
Insufficiently protected credentials in USB provisioning for Intel(R) AMT SDK before version 16.0.3, Intel(R) SCS before version 12.2 and Intel(R) MEBx before versions 11.0.0.0012, 12.0.0.0011, 14.0.0.0004 and 15.0.0.0004 may allow an unauthenticated…
Does this matter?
Lower severity and a low EPSS score (0.25%). Track it; it rarely justifies an emergency change on its own.
Description
Insufficiently protected credentials in USB provisioning for Intel(R) AMT SDK before version 16.0.3, Intel(R) SCS before version 12.2 and Intel(R) MEBx before versions 11.0.0.0012, 12.0.0.0011, 14.0.0.0004 and 15.0.0.0004 may allow an unauthenticated user to potentially enable information disclosure via physical access.
- CVSS 3.1
- 4.6 MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.25% probability · 17th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-522
- Affected
- intel/active management technology software development kit · intel/setup and configuration software · intel/management engine bios extension · intel/core i3 firmware · intel/core i3-1000g1 firmware · intel/core i3-1000g4 firmware · intel/core i3-1000ng4 firmware · intel/core i3-1005g1 firmware · intel/core i3-10100 firmware · intel/core i3-10100e firmware · intel/core i3-10100f firmware · intel/core i3-10100t firmware · intel/core i3-10100te firmware · intel/core i3-10100y firmware · intel/core i3-10105 firmware · intel/core i3-10105f firmware · intel/core i3-10105t firmware · intel/core i3-10110u firmware · intel/core i3-10110y firmware · intel/core i3-10300 firmware · +40 more
- Source
- secure@intel.com
References
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00575.htmlPatch, Vendor Advisory
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00601.htmlPatch, Vendor Advisory
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00575.htmlPatch, Vendor Advisory
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00601.htmlPatch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.