SB2022020924 - Insufficiently protected credentials in Intel AMT SDK, SCS and MEBx
Published: February 9, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Insufficiently protected credentials (CVE-ID: CVE-2021-33107)
The vulnerability allows a local attacker to compromise the target system.
The vulnerability exists due to insufficiently protected credentials in USB provisioning. An attacker with physical access can obtain credentials and gain elevated privileges on the system.
Remediation
Install update from vendor's website.