CVE-2022-21131

MEDIUMCVSS 5.5/10EPSS 0.29%

Last modified

CVE-2022-21131 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. Improper access control for some Intel(R) Xeon(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.. EPSS estimates a 0.29% chance of exploitation in the next 30 days.

Description

Improper access control for some Intel(R) Xeon(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

Metrics

CVSS 3.1
5.5/10

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS Probability
0.29%

20.2th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
IntelCore I9-7940x FirmwareAll versions
IntelCore I9-7960x FirmwareAll versions
IntelCore I9-7980xe FirmwareAll versions
IntelCore I9-7920x FirmwareAll versions
IntelCore I9-7900x FirmwareAll versions
IntelXeon Gold 6138p FirmwareAll versions
IntelXeon Bronze 3104 FirmwareAll versions
IntelXeon Bronze 3106 FirmwareAll versions
IntelXeon Gold 5115 FirmwareAll versions
IntelXeon Gold 5118 FirmwareAll versions
IntelXeon Gold 5119t FirmwareAll versions
IntelXeon Gold 5120 FirmwareAll versions
IntelXeon Gold 5120t FirmwareAll versions
IntelXeon Gold 5122 FirmwareAll versions
IntelXeon Gold 6126 FirmwareAll versions
IntelXeon Gold 6126f FirmwareAll versions
IntelXeon Gold 6126t FirmwareAll versions
IntelXeon Gold 6128 FirmwareAll versions
IntelXeon Gold 6130 FirmwareAll versions
IntelXeon Gold 6130f FirmwareAll versions
IntelXeon Gold 6130t FirmwareAll versions
IntelXeon Gold 6132 FirmwareAll versions
IntelXeon Gold 6134 FirmwareAll versions
IntelXeon Gold 6136 FirmwareAll versions
IntelXeon Gold 6138 FirmwareAll versions
IntelXeon Gold 6138f FirmwareAll versions
IntelXeon Gold 6138t FirmwareAll versions
IntelXeon Gold 6140 FirmwareAll versions
IntelXeon Gold 6142 FirmwareAll versions
IntelXeon Gold 6142f FirmwareAll versions
IntelXeon Gold 6144 FirmwareAll versions
IntelXeon Gold 6146 FirmwareAll versions
IntelXeon Gold 6148 FirmwareAll versions
IntelXeon Gold 6148f FirmwareAll versions
IntelXeon Gold 6150 FirmwareAll versions
IntelXeon Gold 6152 FirmwareAll versions
IntelXeon Gold 6154 FirmwareAll versions
IntelXeon Platinum 8153 FirmwareAll versions
IntelXeon Platinum 8156 FirmwareAll versions
IntelXeon Platinum 8158 FirmwareAll versions
IntelXeon Platinum 8160 FirmwareAll versions
IntelXeon Platinum 8160f FirmwareAll versions
IntelXeon Platinum 8160t FirmwareAll versions
IntelXeon Platinum 8164 FirmwareAll versions
IntelXeon Platinum 8168 FirmwareAll versions
IntelXeon Platinum 8170 FirmwareAll versions
IntelXeon Platinum 8176 FirmwareAll versions
IntelXeon Platinum 8176f FirmwareAll versions
IntelXeon Platinum 8180 FirmwareAll versions
IntelXeon Silver 4108 FirmwareAll versions

Showing 50 of 146 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2022-21131?
Improper access control for some Intel(R) Xeon(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
How severe is CVE-2022-21131?
CVE-2022-21131 has a CVSS score of 5.5/10 (MEDIUM severity). The EPSS model estimates a 0.29% probability of exploitation in the next 30 days.
How do I fix CVE-2022-21131?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-21131?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST