PT-2021-4028 · Intel · Intel Xeon Processors+3
Hugo Magalhaes
·
Published
2021-07-13
·
Updated
2022-02-24
·
CVE-2021-0144
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Intel Xeon Scalable Processors, Intel Xeon Processors D, Intel Xeon Processors E5 v4, Intel Xeon Processors E5 v3, Intel Xeon Processors W (affected versions not specified)
Description
The issue is related to insecure default variable initialization for the Intel BSSA DFT feature, which may allow a privileged user to potentially enable an escalation of privilege via local access. This is due to errors in the initialization of variables.
Recommendations
For Intel Xeon Scalable Processors, Intel Xeon Processors D, Intel Xeon Processors E5 v4, Intel Xeon Processors E5 v3, Intel Xeon Processors W: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Initialization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Intel Xeon Processors
Intel Xeon Processors E5 V3
Intel Xeon Processors E5 V4
Intel Xeon Scalable Processors