CVE-2021-33107
Last modified
CVE-2021-33107 is a medium-severity vulnerability rated 4.6/10 on the CVSS scale. Insufficiently protected credentials in USB provisioning for Intel(R) AMT SDK before version 16.0.3, Intel(R) SCS before version 12.2 and Intel(R) MEBx before versions 11.0.0.0012, 12.0.0.0011, 14.0.0.0004 and 15.0.0.0004 may allow an unauthenticated user to potentially enable information disclosure via physical access.. EPSS estimates a 0.25% chance of exploitation in the next 30 days.
Description
Insufficiently protected credentials in USB provisioning for Intel(R) AMT SDK before version 16.0.3, Intel(R) SCS before version 12.2 and Intel(R) MEBx before versions 11.0.0.0012, 12.0.0.0011, 14.0.0.0004 and 15.0.0.0004 may allow an unauthenticated user to potentially enable information disclosure via physical access.
Metrics
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Intel | Active Management Technology Software Development Kit | < 16.0.3 |
| Intel | Setup And Configuration Software | < 12.2 |
| Intel | Management Engine Bios Extension | < 15.0.0.0004 |
| Intel | Management Engine Bios Extension | < 14.0.0.0004 |
| Intel | Management Engine Bios Extension | < 12.0.0.0011 |
| Intel | Management Engine Bios Extension | < 11.0.0.0012 |
| Intel | Core I3 Firmware | All versions |
| Intel | Core I3-1000g1 Firmware | All versions |
| Intel | Core I3-1000g4 Firmware | All versions |
| Intel | Core I3-1000ng4 Firmware | All versions |
| Intel | Core I3-1005g1 Firmware | All versions |
| Intel | Core I3-10100 Firmware | All versions |
| Intel | Core I3-10100e Firmware | All versions |
| Intel | Core I3-10100f Firmware | All versions |
| Intel | Core I3-10100t Firmware | All versions |
| Intel | Core I3-10100te Firmware | All versions |
| Intel | Core I3-10100y Firmware | All versions |
| Intel | Core I3-10105 Firmware | All versions |
| Intel | Core I3-10105f Firmware | All versions |
| Intel | Core I3-10105t Firmware | All versions |
| Intel | Core I3-10110u Firmware | All versions |
| Intel | Core I3-10110y Firmware | All versions |
| Intel | Core I3-10300 Firmware | All versions |
| Intel | Core I3-10300t Firmware | All versions |
| Intel | Core I3-10305 Firmware | All versions |
| Intel | Core I3-10305t Firmware | All versions |
| Intel | Core I3-10320 Firmware | All versions |
| Intel | Core I3-10325 Firmware | All versions |
| Intel | Core I3 8100 Firmware | All versions |
| Intel | Core I3 8100f Firmware | All versions |
| Intel | Core I3 8100t Firmware | All versions |
| Intel | Core I3 8300 Firmware | All versions |
| Intel | Core I3 8300t Firmware | All versions |
| Intel | Core I3 8350k Firmware | All versions |
| Intel | Core I3 9100 Firmware | All versions |
| Intel | Core I3 9100f Firmware | All versions |
| Intel | Core I3 9100t Firmware | All versions |
| Intel | Core I3 9300 Firmware | All versions |
| Intel | Core I3 9300t Firmware | All versions |
| Intel | Core I3 9320 Firmware | All versions |
| Intel | Core I3 9350k Firmware | All versions |
| Intel | Core I3 9350kf Firmware | All versions |
| Intel | Core I5 Firmware | All versions |
| Intel | Core I5\+8400 Firmware | All versions |
| Intel | Core I5\+8500 Firmware | All versions |
| Intel | Core I5-10110y Firmware | All versions |
| Intel | Core I5-10200h Firmware | All versions |
| Intel | Core I5-10210u Firmware | All versions |
| Intel | Core I5-10210y Firmware | All versions |
| Intel | Core I5-10300h Firmware | All versions |
Showing 50 of 183 affected configurations. See NVD for the full list.
References
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00575.htmlPatch, Vendor Advisory
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00601.htmlPatch, Vendor Advisory
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00575.htmlPatch, Vendor Advisory
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00601.htmlPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-33107?
How severe is CVE-2021-33107?
How do I fix CVE-2021-33107?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-33101Uncontrolled search path in the Intel(R) GPA software before…7.8
- CVE-2021-33102Rejected reason: This is unused.
- CVE-2021-33103Unintended intermediary in the BIOS authenticated code modul…6.7
- CVE-2021-33104Improper access control in the Intel(R) OFU software before …5.5
- CVE-2021-33105Out-of-bounds read in some Intel(R) Core(TM) processors with…5.5
- CVE-2021-33106Integer overflow in the Safestring library maintained by Int…7.8
- CVE-2021-33108Improper input validation in the Intel(R) In-Band Manageabil…6.7
- CVE-2021-33109Rejected reason: This is unused.
- CVE-2021-3311An issue was discovered in October through build 471. It rea…9.8
- CVE-2021-33110Improper input validation for some Intel(R) Wireless Bluetoo…6.5
- CVE-2021-33111Rejected reason: This is unused.
- CVE-2021-33112Rejected reason: This is unused.
Are you affected by CVE-2021-33107?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
