Insufficiently protected credentials in Intel products - CVE-2021-33107
Published: February 9, 2022
Vulnerability identifier: #VU60479
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-33107
CWE-ID: CWE-522
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker to compromise the target system.
The vulnerability exists due to insufficiently protected credentials in USB provisioning. An attacker with physical access can obtain credentials and gain elevated privileges on the system.
Affected software
8th Generation Intel Core Processors
Intel C620 Series Chipset
Intel C420 Chipset
Intel C230 series chipset
Intel 100 Series Chipset
Intel 200 Series Chipset
Intel Management Engine BIOS eXtensions (MEBx)
Pentium Gold processor series (G54XXU)
Intel Celeron Processor 4000 Series
Intel 300 Series Chipset
Intel C240 Series Chipset
Intel Setup and Configuration Software (SCS)
Intel 500 series chipset
Intel 400 Series Chipset
Active Management Technology SDK
Intel C620 Series Chipset
Intel C420 Chipset
Intel C230 series chipset
Intel 100 Series Chipset
Intel 200 Series Chipset
Intel Management Engine BIOS eXtensions (MEBx)
Pentium Gold processor series (G54XXU)
Intel Celeron Processor 4000 Series
Intel 300 Series Chipset
Intel C240 Series Chipset
Intel Setup and Configuration Software (SCS)
Intel 500 series chipset
Intel 400 Series Chipset
Active Management Technology SDK
How to mitigate CVE-2021-33107
Install updates from vendor's website.
8th Generation Intel Core Processors - addressed in versions 11.0.0.0012, 12.0.0.0011
Intel C620 Series Chipset - update to 11.0.0.0012
Intel C420 Chipset - update to 11.0.0.0012
Intel C230 series chipset - update to 11.0.0.0012
Intel 100 Series Chipset - update to 11.0.0.0012
Intel 200 Series Chipset - update to 11.0.0.0012
Intel Management Engine BIOS eXtensions (MEBx) - addressed in versions 11.0.0.0012, 12.0.0.0011, 14.0.0.0004, 15.0.0.0004
Pentium Gold processor series (G54XXU) - update to 12.0.0.0011
Intel Celeron Processor 4000 Series - update to 12.0.0.0011
Intel 300 Series Chipset - update to 12.0.0.0011
Intel C240 Series Chipset - update to 12.0.0.0011
Intel Setup and Configuration Software (SCS) - update to 12.2
Intel 500 series chipset - update to 15.0.0.0004
Intel 400 Series Chipset - update to 15.0.0.0004
Active Management Technology SDK - update to 16.0.3
Intel C620 Series Chipset - update to 11.0.0.0012
Intel C420 Chipset - update to 11.0.0.0012
Intel C230 series chipset - update to 11.0.0.0012
Intel 100 Series Chipset - update to 11.0.0.0012
Intel 200 Series Chipset - update to 11.0.0.0012
Intel Management Engine BIOS eXtensions (MEBx) - addressed in versions 11.0.0.0012, 12.0.0.0011, 14.0.0.0004, 15.0.0.0004
Pentium Gold processor series (G54XXU) - update to 12.0.0.0011
Intel Celeron Processor 4000 Series - update to 12.0.0.0011
Intel 300 Series Chipset - update to 12.0.0.0011
Intel C240 Series Chipset - update to 12.0.0.0011
Intel Setup and Configuration Software (SCS) - update to 12.2
Intel 500 series chipset - update to 15.0.0.0004
Intel 400 Series Chipset - update to 15.0.0.0004
Active Management Technology SDK - update to 16.0.3