Race condition in Intel products - CVE-2022-21198

 

Race condition in Intel products - CVE-2022-21198

Published: November 8, 2022 / Updated: February 22, 2023


Vulnerability identifier: #VU69118
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-21198
CWE-ID: CWE-362
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a race condition in the BIOS firmware. A local user can exploit the race and gain unauthorized access to sensitive information and escalate privileges on the system.


Affected software

11th Generation Intel Core Processors
Intel Xeon W Processors
12th Generation Intel Core Processors
Intel Pentium Gold Processor Series
Intel Celeron Processors
10th Generation Intel Core Processors
Intel Core Processors with Intel Hybrid Technology
Intel Pentium Silver N6000 Processors
Intel Celeron N4000 Processors
Intel Pentium Silver N5000 Processors
Intel Celeron Processor 5000 Series
SIMATIC Field PG M5
SIMATIC Field PG M6
SIMATIC IPC477E Pro
SIMATIC IPC627E
SIMATIC IPC647E
SIMATIC IPC677E
SIMATIC IPC847E
SIMATIC IPC BX-39A
HPE ProLiant MicroServer Gen10 Plus
HPE ProLiant DL20 Gen10 Plus server
HPE ProLiant ML30 Gen10 Plus server
HPE ProLiant m510 Server Cartridge
HP ProLiant ML150 Gen9 Server
HPE ProLiant ML110 Gen9 Server
HPE ProLiant DL560 Gen9 Server
HPE ProLiant DL380 Gen9 Server
HPE ProLiant DL360 Gen9 Server
HPE ProLiant DL120 Gen9 Server
HPE ProLiant DL180 Gen9 Server
HPE ProLiant DL160 Gen9 Server
HPE ProLiant DL80 Gen9 Server
HPE ProLiant DL60 Gen9 Server
HPE ProLiant BL660c Gen9 Server
ProLiant BL480c Server Blade
HPE ProLiant BL460c Gen9 Server Blade
HPE ProLiant ML350 Gen9 Server
SIMATIC IPC427E
SIMATIC IPC477E
SIMATIC ITP1000
EMC Integrated Data Protection Appliance

How to mitigate CVE-2022-21198

Install updates from vendor's website.

HPE ProLiant MicroServer Gen10 Plus - update to 1.64_10-20-2022
HPE ProLiant DL20 Gen10 Plus server - update to 1.64_10-20-2022
HPE ProLiant ML30 Gen10 Plus server - update to 1.64_10-20-2022
HPE ProLiant m510 Server Cartridge - update to 1.96_10-13-2022
HP ProLiant ML150 Gen9 Server - update to 3.04_08-04-2022
HPE ProLiant ML110 Gen9 Server - update to 3.04_08-04-2022
HPE ProLiant DL560 Gen9 Server - update to 3.04_08-04-2022
HPE ProLiant DL380 Gen9 Server - update to 3.04_08-04-2022
HPE ProLiant DL360 Gen9 Server - update to 3.04_08-04-2022
HPE ProLiant DL120 Gen9 Server - update to 3.04_08-04-2022
HPE ProLiant DL180 Gen9 Server - update to 3.04_08-04-2022
HPE ProLiant DL160 Gen9 Server - update to 3.04_08-04-2022
HPE ProLiant DL80 Gen9 Server - update to 3.04_08-04-2022
HPE ProLiant DL60 Gen9 Server - update to 3.04_08-04-2022
HPE ProLiant BL660c Gen9 Server - update to 3.04_08-04-2022
ProLiant BL480c Server Blade - update to 3.04_08-04-2022
HPE ProLiant BL460c Gen9 Server Blade - update to 3.04_08-04-2022
HPE ProLiant ML350 Gen9 Server - update to 3.04_08-04-2022

External References

Related Security Bulletins