PT-2021-4028 · Intel · Intel Xeon Processors+3

Hugo Magalhaes

·

Published

2021-07-13

·

Updated

2022-02-24

·

CVE-2021-0144

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Intel Xeon Scalable Processors, Intel Xeon Processors D, Intel Xeon Processors E5 v4, Intel Xeon Processors E5 v3, Intel Xeon Processors W (affected versions not specified)
Description The issue is related to insecure default variable initialization for the Intel BSSA DFT feature, which may allow a privileged user to potentially enable an escalation of privilege via local access. This is due to errors in the initialization of variables.
Recommendations For Intel Xeon Scalable Processors, Intel Xeon Processors D, Intel Xeon Processors E5 v4, Intel Xeon Processors E5 v3, Intel Xeon Processors W: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Initialization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04555
CVE-2021-0144

Affected Products

Intel Xeon Processors
Intel Xeon Processors E5 V3
Intel Xeon Processors E5 V4
Intel Xeon Scalable Processors