CVE-2021-0187

HIGHCVSS 8.2/10EPSS 0.21%

Last modified

CVE-2021-0187 is a high-severity vulnerability rated 8.2/10 on the CVSS scale. Improper access control in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access.. EPSS estimates a 0.21% chance of exploitation in the next 30 days.

Description

Improper access control in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access.

Metrics

CVSS 3.1
8.2/10

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

EPSS Probability
0.21%

11.6th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
IntelXeon Gold 6342 FirmwareAll versions
IntelXeon Gold 6346 FirmwareAll versions
IntelXeon Gold 6330 FirmwareAll versions
IntelXeon Platinum 8360y FirmwareAll versions
IntelXeon Gold 6354 FirmwareAll versions
IntelXeon Gold 6314u FirmwareAll versions
IntelXeon Gold 6338n FirmwareAll versions
IntelXeon Silver 4314 FirmwareAll versions
IntelXeon Silver 4316 FirmwareAll versions
IntelXeon Gold 5318y FirmwareAll versions
IntelXeon Gold 5317 FirmwareAll versions
IntelXeon Gold 6334 FirmwareAll versions
IntelXeon Gold 6326 FirmwareAll versions
IntelXeon Silver 4309y FirmwareAll versions
IntelXeon Gold 6348 FirmwareAll versions
IntelXeon Silver 4310 FirmwareAll versions
IntelXeon Gold 6338t FirmwareAll versions
IntelXeon Gold 5318s FirmwareAll versions
IntelXeon Gold 6336y FirmwareAll versions
IntelXeon Gold 5318n FirmwareAll versions
IntelXeon Gold 6312u FirmwareAll versions
IntelXeon Silver 4310t FirmwareAll versions
IntelXeon Gold 5320t FirmwareAll versions
IntelXeon Gold 5320 FirmwareAll versions
IntelXeon Gold 5315y FirmwareAll versions
IntelXeon Platinum 8352m FirmwareAll versions
IntelXeon Platinum 8362 FirmwareAll versions
IntelXeon Platinum 8368 FirmwareAll versions
IntelXeon Platinum 8358 FirmwareAll versions
IntelXeon Platinum 8352y FirmwareAll versions
IntelXeon Gold 6338 FirmwareAll versions
IntelXeon Gold 6330n FirmwareAll versions
IntelXeon Platinum 8380 FirmwareAll versions
IntelXeon Platinum 8351n FirmwareAll versions
IntelXeon Platinum 8368q FirmwareAll versions
IntelXeon Platinum 8352s FirmwareAll versions
IntelXeon Platinum 8358p FirmwareAll versions
IntelXeon Platinum 8352v FirmwareAll versions
IntelXeon Platinum 8360hl FirmwareAll versions
IntelXeon Platinum 8360h FirmwareAll versions
IntelXeon Platinum 8356h FirmwareAll versions
IntelXeon Gold 6330h FirmwareAll versions
IntelXeon Platinum 8380h FirmwareAll versions
IntelXeon Gold 5318h FirmwareAll versions
IntelXeon Gold 6328h FirmwareAll versions
IntelXeon Gold 5320h FirmwareAll versions
IntelXeon Platinum 8353h FirmwareAll versions
IntelXeon Platinum 8354h FirmwareAll versions
IntelXeon Gold 6348h FirmwareAll versions
IntelXeon Platinum 8376h FirmwareAll versions

Showing 50 of 53 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2021-0187?
Improper access control in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access.
How severe is CVE-2021-0187?
CVE-2021-0187 has a CVSS score of 8.2/10 (HIGH severity). The EPSS model estimates a 0.21% probability of exploitation in the next 30 days.
How do I fix CVE-2021-0187?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-0187?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST