PT-2022-4322 · Intel+3 · 3Rd Generation Intel Xeon Scalable Processors+3

Published

2022-05-10

·

Updated

2022-10-26

·

CVE-2021-33117

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions 3rd Generation Intel(R) Xeon(R) Scalable Processors versions before MR7
Description The issue is related to improper access control in the BIOS microcode of Intel processors, which may allow a local attacker to potentially enable information disclosure via local access. This could lead to the disclosure of protected information.
Recommendations For 3rd Generation Intel(R) Xeon(R) Scalable Processors versions before MR7, update the BIOS to version MR7 or later to resolve the issue. As a temporary workaround, consider restricting local access to minimize the risk of exploitation.

Fix

Improper Initialization

Weakness Enumeration

Related Identifiers

BDU:2022-04582
BDU:2022-05180
CVE-2021-33117
USN-5486-1
USN-5535-1

Affected Products

3Rd Generation Intel Xeon Scalable Processors
Astra Linux
Linuxmint
Ubuntu