MEDIUM · 4.6

CVE-2021-33107

Insufficiently protected credentials in USB provisioning for Intel(R) AMT SDK before version 16.0.3, Intel(R) SCS before version 12.2 and Intel(R) MEBx before versions 11.0.0.0012, 12.0.0.0011, 14.0.0...

Vulnerability Description

Insufficiently protected credentials in USB provisioning for Intel(R) AMT SDK before version 16.0.3, Intel(R) SCS before version 12.2 and Intel(R) MEBx before versions 11.0.0.0012, 12.0.0.0011, 14.0.0.0004 and 15.0.0.0004 may allow an unauthenticated user to potentially enable information disclosure via physical access.

CVSS Score

4.6

MEDIUM

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
PHYSICAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
IntelActive Management Technology Software Development Kit< 16.0.3
IntelSetup And Configuration Software< 12.2
IntelManagement Engine Bios Extension< 15.0.0.0004
IntelB560-
IntelH510-
IntelH570-
IntelQ570-
IntelW580-
IntelZ590-
IntelB460-
IntelH410-
IntelH420E-
IntelH470-
IntelQ470-
IntelQ470E-
IntelW480-
IntelW480E-
IntelZ490-
IntelC242-
IntelC246-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-33107?

CVE-2021-33107 is a vulnerability with a CVSS score of 4.6 (MEDIUM). Insufficiently protected credentials in USB provisioning for Intel(R) AMT SDK before version 16.0.3, Intel(R) SCS before version 12.2 and Intel(R) MEBx before versions 11.0.0.0012, 12.0.0.0011, 14.0.0...

How severe is CVE-2021-33107?

CVE-2021-33107 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-33107?

Check the references section above for vendor advisories and patch information. Affected products include: Intel Active Management Technology Software Development Kit, Intel Setup And Configuration Software, Intel Management Engine Bios Extension, Intel B560, Intel H510.