MEDIUM · 6.6

CVE-2021-0060

Insufficient compartmentalization in HECI subsystem for the Intel(R) SPS before versions SPS_E5_04.01.04.516.0, SPS_E5_04.04.04.033.0, SPS_E5_04.04.03.281.0, SPS_E5_03.01.03.116.0, SPS_E3_05.01.04.309...

Vulnerability Description

Insufficient compartmentalization in HECI subsystem for the Intel(R) SPS before versions SPS_E5_04.01.04.516.0, SPS_E5_04.04.04.033.0, SPS_E5_04.04.03.281.0, SPS_E5_03.01.03.116.0, SPS_E3_05.01.04.309.0, SPS_02.04.00.101.0, SPS_SoC-A_05.00.03.114.0, SPS_SoC-X_04.00.04.326.0, SPS_SoC-X_03.00.03.117.0, IGN_E5_91.00.00.167.0, SPS_PHI_03.01.03.078.0 may allow an authenticated user to potentially enable escalation of privilege via physical access.

CVSS Score

6.6

MEDIUM

CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
PHYSICAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
IntelC620A Series Firmware< sps_e5_04.04.03.281.0
IntelC621A-
IntelC627A-
IntelC629A-
IntelC620 Series Firmware< sps_e5_04.01.04.516.0
IntelC621-
IntelC622-
IntelC624-
IntelC625-
IntelC626-
IntelC627-
IntelC628-
IntelC629-
IntelC240 Series Firmware< sps_e3_05.01.04.309.0
IntelC242-
IntelC246-
IntelCm246-
IntelAtom P5000 Series Firmware< sps_soc-a_05.00.03.114.0
IntelAtom P5921BAll versions
IntelAtom P5931BAll versions

References

FAQ

What is CVE-2021-0060?

CVE-2021-0060 is a vulnerability with a CVSS score of 6.6 (MEDIUM). Insufficient compartmentalization in HECI subsystem for the Intel(R) SPS before versions SPS_E5_04.01.04.516.0, SPS_E5_04.04.04.033.0, SPS_E5_04.04.03.281.0, SPS_E5_03.01.03.116.0, SPS_E3_05.01.04.309...

How severe is CVE-2021-0060?

CVE-2021-0060 has been rated MEDIUM with a CVSS base score of 6.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-0060?

Check the references section above for vendor advisories and patch information. Affected products include: Intel C620A Series Firmware, Intel C621A, Intel C627A, Intel C629A, Intel C620 Series Firmware.