CVE-2021-33107

MEDIUMCVSS 4.6/10EPSS 0.25%

Last modified

CVE-2021-33107 is a medium-severity vulnerability rated 4.6/10 on the CVSS scale. Insufficiently protected credentials in USB provisioning for Intel(R) AMT SDK before version 16.0.3, Intel(R) SCS before version 12.2 and Intel(R) MEBx before versions 11.0.0.0012, 12.0.0.0011, 14.0.0.0004 and 15.0.0.0004 may allow an unauthenticated user to potentially enable information disclosure via physical access.. EPSS estimates a 0.25% chance of exploitation in the next 30 days.

Description

Insufficiently protected credentials in USB provisioning for Intel(R) AMT SDK before version 16.0.3, Intel(R) SCS before version 12.2 and Intel(R) MEBx before versions 11.0.0.0012, 12.0.0.0011, 14.0.0.0004 and 15.0.0.0004 may allow an unauthenticated user to potentially enable information disclosure via physical access.

Metrics

CVSS 3.1
4.6/10

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS Probability
0.25%

15.8th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
IntelActive Management Technology Software Development Kit< 16.0.3
IntelSetup And Configuration Software< 12.2
IntelManagement Engine Bios Extension< 15.0.0.0004
IntelManagement Engine Bios Extension< 14.0.0.0004
IntelManagement Engine Bios Extension< 12.0.0.0011
IntelManagement Engine Bios Extension< 11.0.0.0012
IntelCore I3 FirmwareAll versions
IntelCore I3-1000g1 FirmwareAll versions
IntelCore I3-1000g4 FirmwareAll versions
IntelCore I3-1000ng4 FirmwareAll versions
IntelCore I3-1005g1 FirmwareAll versions
IntelCore I3-10100 FirmwareAll versions
IntelCore I3-10100e FirmwareAll versions
IntelCore I3-10100f FirmwareAll versions
IntelCore I3-10100t FirmwareAll versions
IntelCore I3-10100te FirmwareAll versions
IntelCore I3-10100y FirmwareAll versions
IntelCore I3-10105 FirmwareAll versions
IntelCore I3-10105f FirmwareAll versions
IntelCore I3-10105t FirmwareAll versions
IntelCore I3-10110u FirmwareAll versions
IntelCore I3-10110y FirmwareAll versions
IntelCore I3-10300 FirmwareAll versions
IntelCore I3-10300t FirmwareAll versions
IntelCore I3-10305 FirmwareAll versions
IntelCore I3-10305t FirmwareAll versions
IntelCore I3-10320 FirmwareAll versions
IntelCore I3-10325 FirmwareAll versions
IntelCore I3 8100 FirmwareAll versions
IntelCore I3 8100f FirmwareAll versions
IntelCore I3 8100t FirmwareAll versions
IntelCore I3 8300 FirmwareAll versions
IntelCore I3 8300t FirmwareAll versions
IntelCore I3 8350k FirmwareAll versions
IntelCore I3 9100 FirmwareAll versions
IntelCore I3 9100f FirmwareAll versions
IntelCore I3 9100t FirmwareAll versions
IntelCore I3 9300 FirmwareAll versions
IntelCore I3 9300t FirmwareAll versions
IntelCore I3 9320 FirmwareAll versions
IntelCore I3 9350k FirmwareAll versions
IntelCore I3 9350kf FirmwareAll versions
IntelCore I5 FirmwareAll versions
IntelCore I5\+8400 FirmwareAll versions
IntelCore I5\+8500 FirmwareAll versions
IntelCore I5-10110y FirmwareAll versions
IntelCore I5-10200h FirmwareAll versions
IntelCore I5-10210u FirmwareAll versions
IntelCore I5-10210y FirmwareAll versions
IntelCore I5-10300h FirmwareAll versions

Showing 50 of 183 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2021-33107?
Insufficiently protected credentials in USB provisioning for Intel(R) AMT SDK before version 16.0.3, Intel(R) SCS before version 12.2 and Intel(R) MEBx before versions 11.0.0.0012, 12.0.0.0011, 14.0.0.0004 and 15.0.0.0004 may allow an unauthenticated user to potentially enable information disclosure via physical access.
How severe is CVE-2021-33107?
CVE-2021-33107 has a CVSS score of 4.6/10 (MEDIUM severity). The EPSS model estimates a 0.25% probability of exploitation in the next 30 days.
How do I fix CVE-2021-33107?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-33107?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST