SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-21131

Improper access control for some Intel(R) Xeon(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

MEDIUM 5.5EPSS 0.30%

Does this matter?

Lower severity and a low EPSS score (0.30%). Track it; it rarely justifies an emergency change on its own.

Description

Improper access control for some Intel(R) Xeon(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVSS 3.1
5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
0.30% probability · 22th percentile
CISA KEV
Not listed
Affected
intel/core i9-7940x firmware · intel/core i9-7960x firmware · intel/core i9-7980xe firmware · intel/core i9-7920x firmware · intel/core i9-7900x firmware · intel/xeon gold 6138p firmware · intel/xeon bronze 3104 firmware · intel/xeon bronze 3106 firmware · intel/xeon gold 5115 firmware · intel/xeon gold 5118 firmware · intel/xeon gold 5119t firmware · intel/xeon gold 5120 firmware · intel/xeon gold 5120t firmware · intel/xeon gold 5122 firmware · intel/xeon gold 6126 firmware · intel/xeon gold 6126f firmware · intel/xeon gold 6126t firmware · intel/xeon gold 6128 firmware · intel/xeon gold 6130 firmware · intel/xeon gold 6130f firmware · +40 more
Source
secure@intel.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.