Input validation error in Intel products - CVE-2021-0174
Published: February 10, 2022
Vulnerability identifier: #VU60507
CSH Severity: Low
CVSS v4: 6 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-0174
CWE-ID: CWE-20
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper use of validation framework in firmware. A remote attacker on the local network can pass specially crafted input to the application and perform a denial of service (DoS) attack.
Affected software
Intel Wi-Fi 6E AX210
Intel Wi-Fi 6 AX201
Intel Wi-Fi 6 AX200
Intel Wireless-AC 9560
Intel Wireless-AC 9462
Intel Wireless-AC 9461
Intel Wireless-AC 9260
Intel Dual Band Wireless-AC 8265
Intel Dual Band Wireless-AC 8260
Intel Dual Band Wireless-AC 3168
Intel Wireless 7265 (Rev D) Family
Intel Dual Band Wireless-AC 3165
Intel Wi-Fi 6 AX210
Killer Wi-Fi 6E AX1675
Killer Wi-Fi 6 AX1650
Killer Wireless-AC 1550
Killer
Intel Active Management Technology Wireless
Intel PROSet/Wireless WiFi Software for Windows
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Realtime Extension
kernel-firmware
ucode-amd
Intel Wi-Fi 6 AX201
Intel Wi-Fi 6 AX200
Intel Wireless-AC 9560
Intel Wireless-AC 9462
Intel Wireless-AC 9461
Intel Wireless-AC 9260
Intel Dual Band Wireless-AC 8265
Intel Dual Band Wireless-AC 8260
Intel Dual Band Wireless-AC 3168
Intel Wireless 7265 (Rev D) Family
Intel Dual Band Wireless-AC 3165
Intel Wi-Fi 6 AX210
Killer Wi-Fi 6E AX1675
Killer Wi-Fi 6 AX1650
Killer Wireless-AC 1550
Killer
Intel Active Management Technology Wireless
Intel PROSet/Wireless WiFi Software for Windows
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Realtime Extension
kernel-firmware
ucode-amd
How to mitigate CVE-2021-0174
Install updates from vendor's website.
Killer - update to 3.0
Intel Active Management Technology Wireless - addressed in versions 11.8.90, 12.0.85, 14.1.60, 15.0.35
Intel PROSet/Wireless WiFi Software for Windows - update to 22.60
kernel-firmware - update to 20200107-3.26.1
ucode-amd - update to 20200107-3.26.1
Intel Active Management Technology Wireless - addressed in versions 11.8.90, 12.0.85, 14.1.60, 15.0.35
Intel PROSet/Wireless WiFi Software for Windows - update to 22.60
kernel-firmware - update to 20200107-3.26.1
ucode-amd - update to 20200107-3.26.1