Improper Authentication in Converged Security and Management Engine (CSME) and Intel Active Management Technology - CVE-2021-33159
Published: November 15, 2022
Vulnerability identifier: #VU69314
CSH Severity: Low
CVSS v4: 5.2 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-33159
CWE-ID: CWE-287
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to bypass authentication process.
The vulnerability exists due to an error in when processing authentication requests in firmware. A local administrator can bypass authentication process and gain elevated privileges on the system.
Affected software
Converged Security and Management Engine (CSME)
Intel Active Management Technology
HPE ProLiant DL20 Gen9 Server SPS
HPE ProLiant ML30 Gen9 Server SPS
HPE ProLiant MicroServer Gen10 Plus
HPE ProLiant DL20 Gen10 Plus server
HPE ProLiant ML30 Gen10 Plus server
EGW-5200
Avamar Data Store Gen5A
Intel Active Management Technology
HPE ProLiant DL20 Gen9 Server SPS
HPE ProLiant ML30 Gen9 Server SPS
HPE ProLiant MicroServer Gen10 Plus
HPE ProLiant DL20 Gen10 Plus server
HPE ProLiant ML30 Gen10 Plus server
EGW-5200
Avamar Data Store Gen5A
How to mitigate CVE-2021-33159
Install updates from vendor's website.
Converged Security and Management Engine (CSME) - addressed in versions 11.8.93, 11.12.93, 11.22.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25
Intel Active Management Technology - addressed in versions 11.8.93, 11.22.93, 12.0.92, 14.1.67, 15.0.42, 16.0
HPE ProLiant DL20 Gen9 Server SPS - update to SPS_E3_04.01.04.700.0
HPE ProLiant ML30 Gen9 Server SPS - update to SPS_E3_04.01.04.700.0
HPE ProLiant MicroServer Gen10 Plus - update to SPS_E3_06.00.03.204.0
HPE ProLiant DL20 Gen10 Plus server - update to SPS_E3_06.00.03.204.0
HPE ProLiant ML30 Gen10 Plus server - update to SPS_E3_06.00.03.204.0
EGW-5200 - update to 1.06.10 2V4
Intel Active Management Technology - addressed in versions 11.8.93, 11.22.93, 12.0.92, 14.1.67, 15.0.42, 16.0
HPE ProLiant DL20 Gen9 Server SPS - update to SPS_E3_04.01.04.700.0
HPE ProLiant ML30 Gen9 Server SPS - update to SPS_E3_04.01.04.700.0
HPE ProLiant MicroServer Gen10 Plus - update to SPS_E3_06.00.03.204.0
HPE ProLiant DL20 Gen10 Plus server - update to SPS_E3_06.00.03.204.0
HPE ProLiant ML30 Gen10 Plus server - update to SPS_E3_06.00.03.204.0
EGW-5200 - update to 1.06.10 2V4