Vulnerability Name:

CVE-2021-33060 (CCN-233114)

Assigned:2021-05-18
Published:2022-08-09
Updated:2022-10-29
Summary:Out-of-bounds write in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via local access.
CVSS v3 Severity:7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
6.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
7.8 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H)
6.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): High
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:6.0 Medium (CCN CVSS v2 Vector: AV:L/AC:H/Au:S/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): High
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-787
Vulnerability Consequences:Gain Privileges
References:Source: MITRE
Type: CNA
CVE-2021-33060

Source: XF
Type: UNKNOWN
intel-cve202133060-priv-esc(233114)

Source: CONFIRM
Type: Third Party Advisory
https://security.netapp.com/advisory/ntap-20220930-0004/

Source: CCN
Type: INTEL-SA-00686
2022.2 IPU – BIOS Advisory

Source: MISC
Type: Vendor Advisory
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00686.html

Vulnerable Configuration:Configuration 1:
  • cpe:/o:intel:xeon_gold_5315y_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_gold_5315y:-:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/o:intel:xeon_gold_5317_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_gold_5317:-:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:intel:xeon_gold_5318n_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_gold_5318n:-:*:*:*:*:*:*:*

  • Configuration 4:
  • cpe:/o:intel:xeon_gold_5318s_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_gold_5318s:-:*:*:*:*:*:*:*

  • Configuration 5:
  • cpe:/o:intel:xeon_gold_5318y_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_gold_5318y:-:*:*:*:*:*:*:*

  • Configuration 6:
  • cpe:/o:intel:xeon_gold_5320_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_gold_5320:-:*:*:*:*:*:*:*

  • Configuration 7:
  • cpe:/o:intel:xeon_gold_5320t_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_gold_5320t:-:*:*:*:*:*:*:*

  • Configuration 8:
  • cpe:/o:intel:xeon_gold_6312u_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_gold_6312u:-:*:*:*:*:*:*:*

  • Configuration 9:
  • cpe:/o:intel:xeon_gold_6314u_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_gold_6314u:-:*:*:*:*:*:*:*

  • Configuration 10:
  • cpe:/o:intel:xeon_gold_6326_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_gold_6326:-:*:*:*:*:*:*:*

  • Configuration 11:
  • cpe:/o:intel:xeon_gold_6330_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_gold_6330:-:*:*:*:*:*:*:*

  • Configuration 12:
  • cpe:/o:intel:xeon_gold_6330n_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_gold_6330n:-:*:*:*:*:*:*:*

  • Configuration 13:
  • cpe:/o:intel:xeon_gold_6334_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_gold_6334:-:*:*:*:*:*:*:*

  • Configuration 14:
  • cpe:/o:intel:xeon_gold_6336y_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_gold_6336y:-:*:*:*:*:*:*:*

  • Configuration 15:
  • cpe:/o:intel:xeon_gold_6338_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_gold_6338:-:*:*:*:*:*:*:*

  • Configuration 16:
  • cpe:/o:intel:xeon_gold_6338n_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_gold_6338n:-:*:*:*:*:*:*:*

  • Configuration 17:
  • cpe:/o:intel:xeon_gold_6338t_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_gold_6338t:-:*:*:*:*:*:*:*

  • Configuration 18:
  • cpe:/o:intel:xeon_gold_6342_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_gold_6342:-:*:*:*:*:*:*:*

  • Configuration 19:
  • cpe:/o:intel:xeon_gold_6346_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_gold_6346:-:*:*:*:*:*:*:*

  • Configuration 20:
  • cpe:/o:intel:xeon_gold_6348_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_gold_6348:-:*:*:*:*:*:*:*

  • Configuration 21:
  • cpe:/o:intel:xeon_gold_6354_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_gold_6354:-:*:*:*:*:*:*:*

  • Configuration 22:
  • cpe:/o:intel:xeon_platinum_8351n_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_platinum_8351n:-:*:*:*:*:*:*:*

  • Configuration 23:
  • cpe:/o:intel:xeon_platinum_8352m_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_platinum_8352m:-:*:*:*:*:*:*:*

  • Configuration 24:
  • cpe:/o:intel:xeon_platinum_8352s_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_platinum_8352s:-:*:*:*:*:*:*:*

  • Configuration 25:
  • cpe:/o:intel:xeon_platinum_8352v_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_platinum_8352v:-:*:*:*:*:*:*:*

  • Configuration 26:
  • cpe:/o:intel:xeon_platinum_8352y_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_platinum_8352y:-:*:*:*:*:*:*:*

  • Configuration 27:
  • cpe:/o:intel:xeon_platinum_8358_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_platinum_8358:-:*:*:*:*:*:*:*

  • Configuration 28:
  • cpe:/o:intel:xeon_platinum_8358p_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_platinum_8358p:-:*:*:*:*:*:*:*

  • Configuration 29:
  • cpe:/o:intel:xeon_platinum_8360y_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_platinum_8360y:-:*:*:*:*:*:*:*

  • Configuration 30:
  • cpe:/o:intel:xeon_platinum_8362_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_platinum_8362:-:*:*:*:*:*:*:*

  • Configuration 31:
  • cpe:/o:intel:xeon_platinum_8368_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_platinum_8368:-:*:*:*:*:*:*:*

  • Configuration 32:
  • cpe:/o:intel:xeon_platinum_8368q_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_platinum_8368q:-:*:*:*:*:*:*:*

  • Configuration 33:
  • cpe:/o:intel:xeon_platinum_8380_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_platinum_8380:-:*:*:*:*:*:*:*

  • Configuration 34:
  • cpe:/o:intel:xeon_silver_4309y_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_silver_4309y:-:*:*:*:*:*:*:*

  • Configuration 35:
  • cpe:/o:intel:xeon_silver_4310_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_silver_4310:-:*:*:*:*:*:*:*

  • Configuration 36:
  • cpe:/o:intel:xeon_silver_4310t_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_silver_4310t:-:*:*:*:*:*:*:*

  • Configuration 37:
  • cpe:/o:intel:xeon_silver_4314_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_silver_4314:-:*:*:*:*:*:*:*

  • Configuration 38:
  • cpe:/o:intel:xeon_silver_4316_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_silver_4316:-:*:*:*:*:*:*:*

  • Configuration 39:
  • cpe:/o:intel:xeon_gold_6330h_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_gold_6330h:-:*:*:*:*:*:*:*

  • Configuration 40:
  • cpe:/o:intel:xeon_platinum_8356h_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_platinum_8356h:-:*:*:*:*:*:*:*

  • Configuration 41:
  • cpe:/o:intel:xeon_platinum_8360h_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_platinum_8360h:-:*:*:*:*:*:*:*

  • Configuration 42:
  • cpe:/o:intel:xeon_platinum_8360hl_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_platinum_8360hl:-:*:*:*:*:*:*:*

  • Configuration 43:
  • cpe:/o:intel:xeon_gold_5318h_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_gold_5318h:-:*:*:*:*:*:*:*

  • Configuration 44:
  • cpe:/o:intel:xeon_gold_5320h_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_gold_5320h:-:*:*:*:*:*:*:*

  • Configuration 45:
  • cpe:/o:intel:xeon_gold_6328h_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_gold_6328h:-:*:*:*:*:*:*:*

  • Configuration 46:
  • cpe:/o:intel:xeon_gold_6328hl_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_gold_6328hl:-:*:*:*:*:*:*:*

  • Configuration 47:
  • cpe:/o:intel:xeon_gold_6348h_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_gold_6348h:-:*:*:*:*:*:*:*

  • Configuration 48:
  • cpe:/o:intel:xeon_platinum_8353h_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_platinum_8353h:-:*:*:*:*:*:*:*

  • Configuration 49:
  • cpe:/o:intel:xeon_platinum_8354h_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_platinum_8354h:-:*:*:*:*:*:*:*

  • Configuration 50:
  • cpe:/o:intel:xeon_platinum_8376h_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_platinum_8376h:-:*:*:*:*:*:*:*

  • Configuration 51:
  • cpe:/o:intel:xeon_platinum_8376hl_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_platinum_8376hl:-:*:*:*:*:*:*:*

  • Configuration 52:
  • cpe:/o:intel:xeon_platinum_8380h_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_platinum_8380h:-:*:*:*:*:*:*:*

  • Configuration 53:
  • cpe:/o:intel:xeon_platinum_8380hl_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_platinum_8380hl:-:*:*:*:*:*:*:*

  • Configuration 54:
  • cpe:/o:netapp:aff_c190_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:aff_c190:-:*:*:*:*:*:*:*

  • Configuration 55:
  • cpe:/o:netapp:aff_a200_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:aff_a200:-:*:*:*:*:*:*:*

  • Configuration 56:
  • cpe:/o:netapp:aff_a220_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:aff_a220:-:*:*:*:*:*:*:*

  • Configuration 57:
  • cpe:/o:netapp:aff_a250_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:aff_a250:-:*:*:*:*:*:*:*

  • Configuration 58:
  • cpe:/o:netapp:aff_a300_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:aff_a300:-:*:*:*:*:*:*:*

  • Configuration 59:
  • cpe:/o:netapp:aff_a320_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:aff_a320:-:*:*:*:*:*:*:*

  • Configuration 60:
  • cpe:/o:netapp:aff_a400_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:aff_a400:-:*:*:*:*:*:*:*

  • Configuration 61:
  • cpe:/o:netapp:aff_a700_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:aff_a700:-:*:*:*:*:*:*:*

  • Configuration 62:
  • cpe:/o:netapp:aff_a700s_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:aff_a700s:-:*:*:*:*:*:*:*

  • Configuration 63:
  • cpe:/o:netapp:aff_a800_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:aff_a800:-:*:*:*:*:*:*:*

  • Configuration 64:
  • cpe:/o:netapp:aff_a900_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:aff_a900:-:*:*:*:*:*:*:*

  • Configuration 65:
  • cpe:/o:netapp:fas500f_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:fas500f:-:*:*:*:*:*:*:*

  • Configuration 66:
  • cpe:/o:netapp:fas2600_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:fas2600:-:*:*:*:*:*:*:*

  • Configuration 67:
  • cpe:/o:netapp:fas2700_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:fas2700:-:*:*:*:*:*:*:*

  • Configuration 68:
  • cpe:/o:netapp:fas8200_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:fas8200:-:*:*:*:*:*:*:*

  • Configuration 69:
  • cpe:/o:netapp:fas8300_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:fas8300:-:*:*:*:*:*:*:*

  • Configuration 70:
  • cpe:/o:netapp:fas8700_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:fas8700:-:*:*:*:*:*:*:*

  • Configuration 71:
  • cpe:/o:netapp:fas9000_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:fas9000:-:*:*:*:*:*:*:*

  • Configuration 72:
  • cpe:/o:netapp:fas9500_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:fas9500:-:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    intel xeon gold 5315y firmware -
    intel xeon gold 5315y -
    intel xeon gold 5317 firmware -
    intel xeon gold 5317 -
    intel xeon gold 5318n firmware -
    intel xeon gold 5318n -
    intel xeon gold 5318s firmware -
    intel xeon gold 5318s -
    intel xeon gold 5318y firmware -
    intel xeon gold 5318y -
    intel xeon gold 5320 firmware -
    intel xeon gold 5320 -
    intel xeon gold 5320t firmware -
    intel xeon gold 5320t -
    intel xeon gold 6312u firmware -
    intel xeon gold 6312u -
    intel xeon gold 6314u firmware -
    intel xeon gold 6314u -
    intel xeon gold 6326 firmware -
    intel xeon gold 6326 -
    intel xeon gold 6330 firmware -
    intel xeon gold 6330 -
    intel xeon gold 6330n firmware -
    intel xeon gold 6330n -
    intel xeon gold 6334 firmware -
    intel xeon gold 6334 -
    intel xeon gold 6336y firmware -
    intel xeon gold 6336y -
    intel xeon gold 6338 firmware -
    intel xeon gold 6338 -
    intel xeon gold 6338n firmware -
    intel xeon gold 6338n -
    intel xeon gold 6338t firmware -
    intel xeon gold 6338t -
    intel xeon gold 6342 firmware -
    intel xeon gold 6342 -
    intel xeon gold 6346 firmware -
    intel xeon gold 6346 -
    intel xeon gold 6348 firmware -
    intel xeon gold 6348 -
    intel xeon gold 6354 firmware -
    intel xeon gold 6354 -
    intel xeon platinum 8351n firmware -
    intel xeon platinum 8351n -
    intel xeon platinum 8352m firmware -
    intel xeon platinum 8352m -
    intel xeon platinum 8352s firmware -
    intel xeon platinum 8352s -
    intel xeon platinum 8352v firmware -
    intel xeon platinum 8352v -
    intel xeon platinum 8352y firmware -
    intel xeon platinum 8352y -
    intel xeon platinum 8358 firmware -
    intel xeon platinum 8358 -
    intel xeon platinum 8358p firmware -
    intel xeon platinum 8358p -
    intel xeon platinum 8360y firmware -
    intel xeon platinum 8360y -
    intel xeon platinum 8362 firmware -
    intel xeon platinum 8362 -
    intel xeon platinum 8368 firmware -
    intel xeon platinum 8368 -
    intel xeon platinum 8368q firmware -
    intel xeon platinum 8368q -
    intel xeon platinum 8380 firmware -
    intel xeon platinum 8380 -
    intel xeon silver 4309y firmware -
    intel xeon silver 4309y -
    intel xeon silver 4310 firmware -
    intel xeon silver 4310 -
    intel xeon silver 4310t firmware -
    intel xeon silver 4310t -
    intel xeon silver 4314 firmware -
    intel xeon silver 4314 -
    intel xeon silver 4316 firmware -
    intel xeon silver 4316 -
    intel xeon gold 6330h firmware -
    intel xeon gold 6330h -
    intel xeon platinum 8356h firmware -
    intel xeon platinum 8356h -
    intel xeon platinum 8360h firmware -
    intel xeon platinum 8360h -
    intel xeon platinum 8360hl firmware -
    intel xeon platinum 8360hl -
    intel xeon gold 5318h firmware -
    intel xeon gold 5318h -
    intel xeon gold 5320h firmware -
    intel xeon gold 5320h -
    intel xeon gold 6328h firmware -
    intel xeon gold 6328h -
    intel xeon gold 6328hl firmware -
    intel xeon gold 6328hl -
    intel xeon gold 6348h firmware -
    intel xeon gold 6348h -
    intel xeon platinum 8353h firmware -
    intel xeon platinum 8353h -
    intel xeon platinum 8354h firmware -
    intel xeon platinum 8354h -
    intel xeon platinum 8376h firmware -
    intel xeon platinum 8376h -
    intel xeon platinum 8376hl firmware -
    intel xeon platinum 8376hl -
    intel xeon platinum 8380h firmware -
    intel xeon platinum 8380h -
    intel xeon platinum 8380hl firmware -
    intel xeon platinum 8380hl -
    netapp aff c190 firmware -
    netapp aff c190 -
    netapp aff a200 firmware -
    netapp aff a200 -
    netapp aff a220 firmware -
    netapp aff a220 -
    netapp aff a250 firmware -
    netapp aff a250 -
    netapp aff a300 firmware -
    netapp aff a300 -
    netapp aff a320 firmware -
    netapp aff a320 -
    netapp aff a400 firmware -
    netapp aff a400 -
    netapp aff a700 firmware -
    netapp aff a700 -
    netapp aff a700s firmware -
    netapp aff a700s -
    netapp aff a800 firmware -
    netapp aff a800 -
    netapp aff a900 firmware -
    netapp aff a900 -
    netapp fas500f firmware -
    netapp fas500f -
    netapp fas2600 firmware -
    netapp fas2600 -
    netapp fas2700 firmware -
    netapp fas2700 -
    netapp fas8200 firmware -
    netapp fas8200 -
    netapp fas8300 firmware -
    netapp fas8300 -
    netapp fas8700 firmware -
    netapp fas8700 -
    netapp fas9000 firmware -
    netapp fas9000 -
    netapp fas9500 firmware -
    netapp fas9500 -