Improper Authentication in Intel products - CVE-2021-0133

 

Improper Authentication in Intel products - CVE-2021-0133

Published: June 16, 2021


Vulnerability identifier: #VU54146
CSH Severity: Medium
CVSS v4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-0133
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to key exchange without entity authentication. A remote authenticated attacker can bypass authentication process and gain elevated privileges on the system.


Affected software

3rd Generation Intel Xeon Scalable Processors
2nd Generation Intel Xeon Scalable Processors
1st Generation Intel Xeon Scalable processor
Intel Xeon W processor 3200 series
Intel Xeon W processor 3100 series
Intel Security Library

How to mitigate CVE-2021-0133

Install updates from vendor's website.

Intel Security Library - update to 3.3

External References

Related Security Bulletins