Cryptographic issues in Intel products - CVE-2021-0131

 

Cryptographic issues in Intel products - CVE-2021-0131

Published: June 16, 2021


Vulnerability identifier: #VU54148
CSH Severity: Medium
CVSS v4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-0131
CWE-ID: CWE-310
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to use of cryptographically weak pseudo-random number generator (PRNG) in an API. A remote authenticated attacker can gain unauthorized access to sensitive information on the system.


Affected software

3rd Generation Intel Xeon Scalable Processors
2nd Generation Intel Xeon Scalable Processors
1st Generation Intel Xeon Scalable processor
Intel Xeon W processor 3200 series
Intel Xeon W processor 3100 series
Intel Security Library

How to mitigate CVE-2021-0131

Install updates from vendor's website.

Intel Security Library - update to 3.3

External References

Related Security Bulletins