CVE-2022-33196
Last modified
CVE-2022-33196 is a medium-severity vulnerability rated 6.7/10 on the CVSS scale. Incorrect default permissions in some memory controller configurations for some Intel(R) Xeon(R) Processors when using Intel(R) Software Guard Extensions which may allow a privileged user to potentially enable escalation of privilege via local access.. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
Incorrect default permissions in some memory controller configurations for some Intel(R) Xeon(R) Processors when using Intel(R) Software Guard Extensions which may allow a privileged user to potentially enable escalation of privilege via local access.
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Intel | Xeon Gold 5315y Firmware | All versions |
| Intel | Xeon Gold 5317 Firmware | All versions |
| Intel | Xeon Gold 5318n Firmware | All versions |
| Intel | Xeon Gold 5318s Firmware | All versions |
| Intel | Xeon Gold 5318y Firmware | All versions |
| Intel | Xeon Gold 5320 Firmware | All versions |
| Intel | Xeon Gold 5320t Firmware | All versions |
| Intel | Xeon Gold 6312u Firmware | All versions |
| Intel | Xeon Gold 6314u Firmware | All versions |
| Intel | Xeon Gold 6326 Firmware | All versions |
| Intel | Xeon Gold 6330 Firmware | All versions |
| Intel | Xeon Gold 6330n Firmware | All versions |
| Intel | Xeon Gold 6334 Firmware | All versions |
| Intel | Xeon Gold 6336y Firmware | All versions |
| Intel | Xeon Gold 6338 Firmware | All versions |
| Intel | Xeon Gold 6338n Firmware | All versions |
| Intel | Xeon Gold 6338t Firmware | All versions |
| Intel | Xeon Gold 6342 Firmware | All versions |
| Intel | Xeon Gold 6346 Firmware | All versions |
| Intel | Xeon Gold 6348 Firmware | All versions |
| Intel | Xeon Gold 6354 Firmware | All versions |
| Intel | Xeon Platinum 8351n Firmware | All versions |
| Intel | Xeon Platinum 8352m Firmware | All versions |
| Intel | Xeon Platinum 8352s Firmware | All versions |
| Intel | Xeon Platinum 8352v Firmware | All versions |
| Intel | Xeon Platinum 8352y Firmware | All versions |
| Intel | Xeon Platinum 8358 Firmware | All versions |
| Intel | Xeon Platinum 8358p Firmware | All versions |
| Intel | Xeon Platinum 8360y Firmware | All versions |
| Intel | Xeon Platinum 8362 Firmware | All versions |
| Intel | Xeon Platinum 8368 Firmware | All versions |
| Intel | Xeon Platinum 8368q Firmware | All versions |
| Intel | Xeon Platinum 8380 Firmware | All versions |
| Intel | Xeon Silver 4309y Firmware | All versions |
| Intel | Xeon Silver 4310 Firmware | All versions |
| Intel | Xeon Silver 4310t Firmware | All versions |
| Intel | Xeon Silver 4314 Firmware | All versions |
| Intel | Xeon Silver 4316 Firmware | All versions |
| Intel | Xeon Gold 6330h Firmware | All versions |
| Intel | Xeon Platinum 8356h Firmware | All versions |
| Intel | Xeon Platinum 8360h Firmware | All versions |
| Intel | Xeon Platinum 8360hl Firmware | All versions |
| Intel | Xeon Gold 5318h Firmware | All versions |
| Intel | Xeon Gold 5320h Firmware | All versions |
| Intel | Xeon Gold 6328h Firmware | All versions |
| Intel | Xeon Gold 6328hl Firmware | All versions |
| Intel | Xeon Gold 6348h Firmware | All versions |
| Intel | Xeon Platinum 8353h Firmware | All versions |
| Intel | Xeon Platinum 8354h Firmware | All versions |
| Intel | Xeon Platinum 8376h Firmware | All versions |
Showing 50 of 136 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-33196?
How severe is CVE-2022-33196?
How do I fix CVE-2022-33196?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-33190Improper input validation in the Intel(R) SUR software befor…7.8
- CVE-2022-33191Authenticated (contributor or higher user role) Stored Cross…5.4
- CVE-2022-33192Four OS command injection vulnerabilities exist in the XCMD …10
- CVE-2022-33193Four OS command injection vulnerabilities exist in the XCMD …10
- CVE-2022-33194Four OS command injection vulnerabilities exist in the XCMD …10
- CVE-2022-33195Four OS command injection vulnerabilities exist in the XCMD …10
- CVE-2022-33197Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2022-33198Unauthenticated WordPress Options Change vulnerability in Bi…5.3
- CVE-2022-3320It was possible to bypass policies configured for Zero Trust…9.8
- CVE-2022-33200Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2022-33201Cross-Site Request Forgery (CSRF) vulnerability in MailerLit…8.8
- CVE-2022-33202Authentication bypass vulnerability in the setup screen of L…8.1
Are you affected by CVE-2022-33196?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
