SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-33150

Hardware allows activation of test or debug logic at runtime for some Intel(R) Trace Hub instances which may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

MEDIUM 6.8EPSS 0.35%

Does this matter?

Lower severity and a low EPSS score (0.35%). Track it; it rarely justifies an emergency change on its own.

Description

Hardware allows activation of test or debug logic at runtime for some Intel(R) Trace Hub instances which may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

CVSS 3.1
6.8 MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
0.35% probability · 28th percentile
CISA KEV
Not listed
Affected
intel/atom c2308 · intel/atom c2316 · intel/atom c2338 · intel/atom c2350 · intel/atom c2358 · intel/atom c2508 · intel/atom c2516 · intel/atom c2518 · intel/atom c2530 · intel/atom c2538 · intel/atom c2550 · intel/atom c2558 · intel/atom c2718 · intel/atom c2730 · intel/atom c2738 · intel/atom c2750 · intel/atom c2758 · intel/atom c3308 · intel/atom c3336 · intel/atom c3338 · +40 more
Source
secure@intel.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.