MEDIUM · 6.8

CVE-2021-33150

Hardware allows activation of test or debug logic at runtime for some Intel(R) Trace Hub instances which may allow an unauthenticated user to potentially enable escalation of privilege via physical ac...

Vulnerability Description

Hardware allows activation of test or debug logic at runtime for some Intel(R) Trace Hub instances which may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

CVSS Score

6.8

MEDIUM

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
PHYSICAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
IntelAtom C2308-
IntelAtom C2316-
IntelAtom C2338-
IntelAtom C2350-
IntelAtom C2358-
IntelAtom C2508-
IntelAtom C2516-
IntelAtom C2518-
IntelAtom C2530-
IntelAtom C2538-
IntelAtom C2550-
IntelAtom C2558-
IntelAtom C2718-
IntelAtom C2730-
IntelAtom C2738-
IntelAtom C2750-
IntelAtom C2758-
IntelAtom C3308-
IntelAtom C3336-
IntelAtom C3338-

References

FAQ

What is CVE-2021-33150?

CVE-2021-33150 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Hardware allows activation of test or debug logic at runtime for some Intel(R) Trace Hub instances which may allow an unauthenticated user to potentially enable escalation of privilege via physical ac...

How severe is CVE-2021-33150?

CVE-2021-33150 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-33150?

Check the references section above for vendor advisories and patch information. Affected products include: Intel Atom C2308, Intel Atom C2316, Intel Atom C2338, Intel Atom C2350, Intel Atom C2358.