MEDIUM · 4.4

CVE-2021-0148

Insertion of information into log file in firmware for some Intel(R) SSD DC may allow a privileged user to potentially enable information disclosure via local access.

Vulnerability Description

Insertion of information into log file in firmware for some Intel(R) SSD DC may allow a privileged user to potentially enable information disclosure via local access.

CVSS Score

4.4

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
IntelSsd Dc D4512 Firmware< et10
IntelSsd Dc D4512-
IntelSsd Dc P4510 U.2 Firmware< vdv10182
IntelSsd Dc P4510 U.2-
IntelSsd Dc P4510 Edsff Firmware< vdv10284
IntelSsd Dc P4510 Edsff-
IntelSsd Dc P4511 Edsff Firmware< vdv10284
IntelSsd Dc P4511 Edsff-
IntelSsd Dc P4511 M.2 Firmware< vdv10384
IntelSsd Dc P4511 M.2-
IntelSsd Dc P4610 U.2 Firmware< vdv10182
IntelSsd Dc P4610 U.2-
IntelSsd Dc P4618 Firmware< vdv10182
IntelSsd Dc P4618-
IntelSsd D-S4510 Firmware< xcv10140
IntelSsd D-S4510-
IntelSsd D7-P5608 Firmware< 2cv1r106
IntelSsd D7-P5608-
IntelSsd D7-P5500 Firmware< 1.2.0
IntelSsd D7-P5500-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-0148?

CVE-2021-0148 is a vulnerability with a CVSS score of 4.4 (MEDIUM). Insertion of information into log file in firmware for some Intel(R) SSD DC may allow a privileged user to potentially enable information disclosure via local access.

How severe is CVE-2021-0148?

CVE-2021-0148 has been rated MEDIUM with a CVSS base score of 4.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-0148?

Check the references section above for vendor advisories and patch information. Affected products include: Intel Ssd Dc D4512 Firmware, Intel Ssd Dc D4512, Intel Ssd Dc P4510 U.2 Firmware, Intel Ssd Dc P4510 U.2, Intel Ssd Dc P4510 Edsff Firmware.