CVE-2021-0159

HIGHCVSS 7.8/10EPSS 0.26%

Last modified

CVE-2021-0159 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Improper input validation in the BIOS authenticated code module for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.. EPSS estimates a 0.26% chance of exploitation in the next 30 days.

Description

Improper input validation in the BIOS authenticated code module for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.

Metrics

CVSS 3.1
7.8/10

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.26%

16.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
IntelXeon Bronze 3204 FirmwareAll versions
IntelXeon Bronze 3206r FirmwareAll versions
IntelXeon Gold 5215 FirmwareAll versions
IntelXeon Gold 5215l FirmwareAll versions
IntelXeon Gold 5217 FirmwareAll versions
IntelXeon Gold 5218 FirmwareAll versions
IntelXeon Gold 5218b FirmwareAll versions
IntelXeon Gold 5218n FirmwareAll versions
IntelXeon Gold 5218r FirmwareAll versions
IntelXeon Gold 5218t FirmwareAll versions
IntelXeon Gold 5220 FirmwareAll versions
IntelXeon Gold 5220r FirmwareAll versions
IntelXeon Gold 5220s FirmwareAll versions
IntelXeon Gold 5220t FirmwareAll versions
IntelXeon Gold 5222 FirmwareAll versions
IntelXeon Gold 5315y FirmwareAll versions
IntelXeon Gold 5317 FirmwareAll versions
IntelXeon Gold 5318h FirmwareAll versions
IntelXeon Gold 5318n FirmwareAll versions
IntelXeon Gold 5318s FirmwareAll versions
IntelXeon Gold 5318y FirmwareAll versions
IntelXeon Gold 5320 FirmwareAll versions
IntelXeon Gold 5320h FirmwareAll versions
IntelXeon Gold 5320t FirmwareAll versions
IntelXeon Gold 6208u FirmwareAll versions
IntelXeon Gold 6209u FirmwareAll versions
IntelXeon Gold 6210u FirmwareAll versions
IntelXeon Gold 6212u FirmwareAll versions
IntelXeon Gold 6222v FirmwareAll versions
IntelXeon Gold 6226 FirmwareAll versions
IntelXeon Gold 6226r FirmwareAll versions
IntelXeon Gold 6230 FirmwareAll versions
IntelXeon Gold 6230n FirmwareAll versions
IntelXeon Gold 6230r FirmwareAll versions
IntelXeon Gold 6230t FirmwareAll versions
IntelXeon Gold 6234 FirmwareAll versions
IntelXeon Gold 6238 FirmwareAll versions
IntelXeon Gold 6238l FirmwareAll versions
IntelXeon Gold 6238r FirmwareAll versions
IntelXeon Gold 6238t FirmwareAll versions
IntelXeon Gold 6240 FirmwareAll versions
IntelXeon Gold 6240l FirmwareAll versions
IntelXeon Gold 6240r FirmwareAll versions
IntelXeon Gold 6240y FirmwareAll versions
IntelXeon Gold 6242 FirmwareAll versions
IntelXeon Gold 6242r FirmwareAll versions
IntelXeon Gold 6244 FirmwareAll versions
IntelXeon Gold 6246 FirmwareAll versions
IntelXeon Gold 6246r FirmwareAll versions
IntelXeon Gold 6248 FirmwareAll versions

Showing 50 of 129 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2021-0159?
Improper input validation in the BIOS authenticated code module for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.
How severe is CVE-2021-0159?
CVE-2021-0159 has a CVSS score of 7.8/10 (HIGH severity). The EPSS model estimates a 0.26% probability of exploitation in the next 30 days.
How do I fix CVE-2021-0159?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-0159?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST