Out-of-bounds read in Intel products - CVE-2021-0118
Published: February 15, 2022
Vulnerability identifier: #VU60602
CSH Severity: Low
CVSS v4: 8.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-0118
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition in the firmware. A local administrator can trigger out-of-bounds read error and read contents of memory on the system, leading to privilege escalation.
Affected software
2nd Generation Intel Xeon Scalable Processors
Intel Xeon W Processors
Intel Xeon Processor E Family
Intel Xeon D Processors
11th Generation Intel Core Processors
10th Generation Intel Core Processors
8th Generation Intel Core Processors
7th Generation Intel Core Processors
6th Generation Intel Core Processors
Intel Core X-series Processor Family
Intel Atom Processor C3XXX Family
VEP4600-8 Core
VEP4600-4 Core
VEP4600-16 Core
Intel Xeon Scalable Processors
9th Generation Intel Core Processors
IBM Qradar SIEM
EMC Integrated Data Protection Appliance
F5OS
Dell EMC VxRail Appliance
Integrated System for Microsoft Azure Stack Hub
Intel Xeon W Processors
Intel Xeon Processor E Family
Intel Xeon D Processors
11th Generation Intel Core Processors
10th Generation Intel Core Processors
8th Generation Intel Core Processors
7th Generation Intel Core Processors
6th Generation Intel Core Processors
Intel Core X-series Processor Family
Intel Atom Processor C3XXX Family
VEP4600-8 Core
VEP4600-4 Core
VEP4600-16 Core
Intel Xeon Scalable Processors
9th Generation Intel Core Processors
IBM Qradar SIEM
EMC Integrated Data Protection Appliance
F5OS
Dell EMC VxRail Appliance
Integrated System for Microsoft Azure Stack Hub
How to mitigate CVE-2021-0118
Install updates from vendor's website.
VEP4600-8 Core - update to UFW-3.8
VEP4600-4 Core - update to UFW-3.8
VEP4600-16 Core - update to UFW-3.8
Dell EMC VxRail Appliance - update to 4.5.480
Integrated System for Microsoft Azure Stack Hub - update to 2210
VEP4600-4 Core - update to UFW-3.8
VEP4600-16 Core - update to UFW-3.8
Dell EMC VxRail Appliance - update to 4.5.480
Integrated System for Microsoft Azure Stack Hub - update to 2210
External References
Related Security Bulletins
- Multiple vulnerabilities in Intel Processors
- Multiple vulnerabilities in F5OS BIOS
- Multiple vulnerabilities in Dell VxRail
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in Dell Integrated System for Microsoft Azure Stack Hub
- Multiple vulnerabilities in Dell Networking Products for Intel
- Multiple vulnetabilities in Dell EMC Integrated Data Protection Appliance