PT-2022-3829 · Intel · Intel Ssd Dc+1

Published

2022-05-10

·

Updated

2022-10-07

·

CVE-2021-33080

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Intel(R) SSD DC versions (affected versions not specified) Intel(R) Optane(TM) SSD versions (affected versions not specified) Intel(R) Optane(TM) SSD DC versions (affected versions not specified)
Description The issue is related to the exposure of sensitive system information due to uncleared debug information in firmware for some Intel products. This may allow an unauthenticated user to potentially enable information disclosure or escalation of privilege via physical access. The vulnerability is associated with a lack of protection for service data.
Recommendations For Intel(R) SSD DC, update the firmware to a version that clears debug information. For Intel(R) Optane(TM) SSD, update the firmware to a version that clears debug information. For Intel(R) Optane(TM) SSD DC, update the firmware to a version that clears debug information. As a temporary workaround, consider restricting physical access to the devices until a patch is available.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2022-04628
CVE-2021-33080

Affected Products

Intel Optane Ssd
Intel Ssd Dc