Vulnerability Description
Improper access control for some 3rd Generation Intel(R) Xeon(R) Scalable Processors before BIOS version MR7, may allow a local attacker to potentially enable information disclosure via local access.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Intel | Bios | < mr7 |
| Intel | Xeon Gold 5315Y | - |
| Intel | Xeon Gold 5317 | - |
| Intel | Xeon Gold 5318H | - |
| Intel | Xeon Gold 5318N | - |
| Intel | Xeon Gold 5318S | - |
| Intel | Xeon Gold 5318Y | - |
| Intel | Xeon Gold 5320 | - |
| Intel | Xeon Gold 5320H | - |
| Intel | Xeon Gold 5320T | - |
| Intel | Xeon Gold 6312U | - |
| Intel | Xeon Gold 6314U | - |
| Intel | Xeon Gold 6326 | - |
| Intel | Xeon Gold 6328H | - |
| Intel | Xeon Gold 6328Hl | - |
| Intel | Xeon Gold 6330 | - |
| Intel | Xeon Gold 6330H | - |
| Intel | Xeon Gold 6330N | - |
| Intel | Xeon Gold 6334 | - |
| Intel | Xeon Gold 6336Y | - |
References
- https://security.netapp.com/advisory/ntap-20220818-0001/Third Party Advisory
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00586.Vendor Advisory
- https://security.netapp.com/advisory/ntap-20220818-0001/Third Party Advisory
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00586.Vendor Advisory
FAQ
What is CVE-2021-33117?
CVE-2021-33117 is a vulnerability with a CVSS score of 5.5 (MEDIUM). Improper access control for some 3rd Generation Intel(R) Xeon(R) Scalable Processors before BIOS version MR7, may allow a local attacker to potentially enable information disclosure via local access.
How severe is CVE-2021-33117?
CVE-2021-33117 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-33117?
Check the references section above for vendor advisories and patch information. Affected products include: Intel Bios, Intel Xeon Gold 5315Y, Intel Xeon Gold 5317, Intel Xeon Gold 5318H, Intel Xeon Gold 5318N.