Vulnerability Description
Use of cryptographically weak pseudo-random number generator (PRNG) in an API for the Intel(R) Security Library before version 3.3 may allow an authenticated user to potentially enable information disclosure via network access.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Intel | Secl-Dc | < 3.3 |
| Intel | Xeon Bronze 3104 | - |
| Intel | Xeon Bronze 3106 | - |
| Intel | Xeon Bronze 3204 | - |
| Intel | Xeon Bronze 3206R | - |
| Intel | Xeon Gold 5115 | - |
| Intel | Xeon Gold 5117 | - |
| Intel | Xeon Gold 5117F | - |
| Intel | Xeon Gold 5118 | - |
| Intel | Xeon Gold 5119T | - |
| Intel | Xeon Gold 5120 | - |
| Intel | Xeon Gold 5120T | - |
| Intel | Xeon Gold 5122 | - |
| Intel | Xeon Gold 5215 | - |
| Intel | Xeon Gold 5215L | - |
| Intel | Xeon Gold 5217 | - |
| Intel | Xeon Gold 5218 | - |
| Intel | Xeon Gold 5218B | - |
| Intel | Xeon Gold 5218N | - |
| Intel | Xeon Gold 5218R | - |
Related Weaknesses (CWE)
References
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00521.Vendor Advisory
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00521.Vendor Advisory
FAQ
What is CVE-2021-0131?
CVE-2021-0131 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Use of cryptographically weak pseudo-random number generator (PRNG) in an API for the Intel(R) Security Library before version 3.3 may allow an authenticated user to potentially enable information dis...
How severe is CVE-2021-0131?
CVE-2021-0131 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-0131?
Check the references section above for vendor advisories and patch information. Affected products include: Intel Secl-Dc, Intel Xeon Bronze 3104, Intel Xeon Bronze 3106, Intel Xeon Bronze 3204, Intel Xeon Bronze 3206R.