PT-2022-4324 · Intel · Intel Ssd Dc+2

Published

2022-05-10

·

Updated

2022-10-07

·

CVE-2021-33083

CVSS v2.0

4.9

Medium

VectorAV:L/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Intel SSD versions (affected versions not specified) Intel Optane SSD versions (affected versions not specified) Intel Optane SSD DC versions (affected versions not specified) Intel SSD DC versions (affected versions not specified)
Description The issue is related to improper authentication in the firmware of certain Intel SSD products, which may allow a privileged user to potentially enable information disclosure via local access. This could lead to a "man-in-the-middle" attack, resulting in the exposure of protected information.
Recommendations For Intel SSD, consider restricting local access to minimize the risk of exploitation. For Intel Optane SSD, restrict local access to prevent potential information disclosure. For Intel Optane SSD DC, limit privileged user access until a fix is available. For Intel SSD DC, avoid using local access for sensitive operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2022-05182
CVE-2021-33083

Affected Products

Intel Optane Ssd
Intel Ssd
Intel Ssd Dc