MEDIUM · 5.3

CVE-2021-33076

Improper authentication in firmware for some Intel(R) SSD DC Products may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

Vulnerability Description

Improper authentication in firmware for some Intel(R) SSD DC Products may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

CVSS Score

5.3

MEDIUM

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Attack Vector
PHYSICAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
IntelSsd 600P Firmware< 122c
IntelSsd 600P-
IntelSsd 660P Firmware< 005c
IntelSsd 660P-
IntelSsd 665P Firmware< 002c
IntelSsd 665P-
IntelSsd 670P Firmware< 003c
IntelSsd 670P-
IntelSsd 700P Firmware< 005c
IntelSsd 700P-
IntelSsd 760P Firmware< 006c
IntelSsd 760P-
IntelSsd D3-S4510 M.2 Firmware< xc311132
IntelSsd D3-S4510 M.2-
IntelSsd Dc P4510 Sff Firmware< vdv10184
IntelSsd Dc P4510 Sff-
IntelSsd D3-S4610 M.2 Firmware< xc311132
IntelSsd D3-S4610 M.2-
IntelSsd Dc P4610 Sff Firmware< vdv10184
IntelSsd Dc P4610 Sff-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-33076?

CVE-2021-33076 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Improper authentication in firmware for some Intel(R) SSD DC Products may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

How severe is CVE-2021-33076?

CVE-2021-33076 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-33076?

Check the references section above for vendor advisories and patch information. Affected products include: Intel Ssd 600P Firmware, Intel Ssd 600P, Intel Ssd 660P Firmware, Intel Ssd 660P, Intel Ssd 665P Firmware.