PT-2022-4324 · Intel · Intel Ssd Dc+2
Published
2022-05-10
·
Updated
2022-10-07
·
CVE-2021-33083
CVSS v2.0
4.9
Medium
| Vector | AV:L/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Intel SSD versions (affected versions not specified)
Intel Optane SSD versions (affected versions not specified)
Intel Optane SSD DC versions (affected versions not specified)
Intel SSD DC versions (affected versions not specified)
Description
The issue is related to improper authentication in the firmware of certain Intel SSD products, which may allow a privileged user to potentially enable information disclosure via local access. This could lead to a "man-in-the-middle" attack, resulting in the exposure of protected information.
Recommendations
For Intel SSD, consider restricting local access to minimize the risk of exploitation.
For Intel Optane SSD, restrict local access to prevent potential information disclosure.
For Intel Optane SSD DC, limit privileged user access until a fix is available.
For Intel SSD DC, avoid using local access for sensitive operations until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Authentication
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Intel Optane Ssd
Intel Ssd
Intel Ssd Dc