Vulnerability Name:

CVE-2021-33120 (CCN-219098)

Assigned:2021-05-18
Published:2022-02-08
Updated:2022-02-15
Summary:Out of bounds read under complex microarchitectural condition in memory subsystem for some Intel Atom(R) Processors may allow authenticated user to potentially enable information disclosure or cause denial of service via network access.
CVSS v3 Severity:5.4 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L)
4.7 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): Low
3.6 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L)
3.2 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): High
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:5.5 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): Partial
2.4 Low (CCN CVSS v2 Vector: AV:L/AC:H/Au:S/C:P/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): High
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-125
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2021-33120

Source: XF
Type: UNKNOWN
intel-cve202133120-info-disc(219098)

Source: CCN
Type: IBM Security Bulletin 6845359 (Security QRadar SIEM)
IBM QRadar SIEM Appliances could be vulnerable to multiple Intel CVEs

Source: CCN
Type: INTEL-SA-00589
2021.2 IPU - Intel Atom Processor Advisory

Source: MISC
Type: Mitigation, Vendor Advisory
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00589.html

Vulnerable Configuration:Configuration 1:
  • cpe:/o:intel:atom_p5942b_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:atom_p5942b:-:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/o:intel:atom_p5931b_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:atom_p5931b:-:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:intel:atom_p5962b_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:atom_p5962b:-:*:*:*:*:*:*:*

  • Configuration 4:
  • cpe:/o:intel:atom_p5921b_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:atom_p5921b:-:*:*:*:*:*:*:*

  • Configuration 5:
  • cpe:/o:intel:xeon_d1700_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_d1700:-:*:*:*:*:*:*:*

  • Configuration 6:
  • cpe:/o:intel:xeon_d2700_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:xeon_d2700:-:*:*:*:*:*:*:*

  • Configuration 7:
  • cpe:/o:intel:core_i5-l16g7_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:core_i5-l16g7:-:*:*:*:*:*:*:*

  • Configuration 8:
  • cpe:/o:intel:core_i3-l13g4_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:core_i3-l13g4:-:*:*:*:*:*:*:*

  • Configuration 9:
  • cpe:/o:intel:pentium_j6425_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:pentium_j6425:-:*:*:*:*:*:*:*

  • Configuration 10:
  • cpe:/o:intel:pentium_n6415_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:pentium_n6415:-:*:*:*:*:*:*:*

  • Configuration 11:
  • cpe:/o:intel:celeron_j6413_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:celeron_j6413:-:*:*:*:*:*:*:*

  • Configuration 12:
  • cpe:/o:intel:celeron_n6211_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:celeron_n6211:-:*:*:*:*:*:*:*

  • Configuration 13:
  • cpe:/o:intel:atom_x6413e_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:atom_x6413e:-:*:*:*:*:*:*:*

  • Configuration 14:
  • cpe:/o:intel:atom_x6425re_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:atom_x6425re:-:*:*:*:*:*:*:*

  • Configuration 15:
  • cpe:/o:intel:atom_x6427fe_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:atom_x6427fe:-:*:*:*:*:*:*:*

  • Configuration 16:
  • cpe:/o:intel:atom_x6212re_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:atom_x6212re:-:*:*:*:*:*:*:*

  • Configuration 17:
  • cpe:/o:intel:atom_x6200fe_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:atom_x6200fe:-:*:*:*:*:*:*:*

  • Configuration 18:
  • cpe:/o:intel:atom_x6211e_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:atom_x6211e:-:*:*:*:*:*:*:*

  • Configuration 19:
  • cpe:/o:intel:atom_x6425e_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:atom_x6425e:-:*:*:*:*:*:*:*

  • Configuration 20:
  • cpe:/o:intel:pentium_silver_n6005_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:pentium_silver_n6005:-:*:*:*:*:*:*:*

  • Configuration 21:
  • cpe:/o:intel:pentium_silver_n6000_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:pentium_silver_n6000:-:*:*:*:*:*:*:*

  • Configuration 22:
  • cpe:/o:intel:celeron_n4505_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:celeron_n4505:-:*:*:*:*:*:*:*

  • Configuration 23:
  • cpe:/o:intel:celeron_n4500_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:celeron_n4500:-:*:*:*:*:*:*:*

  • Configuration 24:
  • cpe:/o:intel:celeron_n5105_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:celeron_n5105:-:*:*:*:*:*:*:*

  • Configuration 25:
  • cpe:/o:intel:celeron_n5100_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:celeron_n5100:-:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:ibm:qradar_security_information_and_event_manager:7.4:-:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:7821
    P
    ucode-intel-20230214-150200.21.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:3214
    P
    libmysqlclient18-10.0.40.1-2.9.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94844
    P
    ucode-intel-20220207-10.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:375
    P
    ucode-intel-20220207-10.1 on GA media (Moderate)
    2022-06-10
    oval:org.opensuse.security:def:126969
    P
    Security update for ucode-intel (Important)
    2022-02-25
    oval:org.opensuse.security:def:118819
    P
    Security update for ucode-intel (Important)
    2022-02-25
    oval:org.opensuse.security:def:101643
    P
    Security update for ucode-intel (Important)
    2022-02-25
    oval:org.opensuse.security:def:119497
    P
    Security update for ucode-intel (Important)
    2022-02-25
    oval:org.opensuse.security:def:42344
    P
    Security update for ucode-intel (Important)
    2022-02-25
    oval:org.opensuse.security:def:127367
    P
    Security update for ucode-intel (Important)
    2022-02-25
    oval:org.opensuse.security:def:119009
    P
    Security update for ucode-intel (Important)
    2022-02-25
    oval:org.opensuse.security:def:951
    P
    Security update for ucode-intel (Important)
    2022-02-25
    oval:org.opensuse.security:def:119682
    P
    Security update for ucode-intel (Important)
    2022-02-25
    oval:org.opensuse.security:def:119119
    P
    Security update for ucode-intel (Important)
    2022-02-25
    oval:org.opensuse.security:def:125806
    P
    Security update for ucode-intel (Important)
    2022-02-25
    oval:org.opensuse.security:def:6172
    P
    Security update for ucode-intel (Important)
    2022-02-25
    oval:org.opensuse.security:def:119314
    P
    Security update for ucode-intel (Important)
    2022-02-25
    oval:org.opensuse.security:def:42200
    P
    Security update for ucode-intel (Important)
    2022-02-25
    BACK
    intel atom p5942b firmware -
    intel atom p5942b -
    intel atom p5931b firmware -
    intel atom p5931b -
    intel atom p5962b firmware -
    intel atom p5962b -
    intel atom p5921b firmware -
    intel atom p5921b -
    intel xeon d1700 firmware -
    intel xeon d1700 -
    intel xeon d2700 firmware -
    intel xeon d2700 -
    intel core i5-l16g7 firmware -
    intel core i5-l16g7 -
    intel core i3-l13g4 firmware -
    intel core i3-l13g4 -
    intel pentium j6425 firmware -
    intel pentium j6425 -
    intel pentium n6415 firmware -
    intel pentium n6415 -
    intel celeron j6413 firmware -
    intel celeron j6413 -
    intel celeron n6211 firmware -
    intel celeron n6211 -
    intel atom x6413e firmware -
    intel atom x6413e -
    intel atom x6425re firmware -
    intel atom x6425re -
    intel atom x6427fe firmware -
    intel atom x6427fe -
    intel atom x6212re firmware -
    intel atom x6212re -
    intel atom x6200fe firmware -
    intel atom x6200fe -
    intel atom x6211e firmware -
    intel atom x6211e -
    intel atom x6425e firmware -
    intel atom x6425e -
    intel pentium silver n6005 firmware -
    intel pentium silver n6005 -
    intel pentium silver n6000 firmware -
    intel pentium silver n6000 -
    intel celeron n4505 firmware -
    intel celeron n4505 -
    intel celeron n4500 firmware -
    intel celeron n4500 -
    intel celeron n5105 firmware -
    intel celeron n5105 -
    intel celeron n5100 firmware -
    intel celeron n5100 -
    ibm qradar security information and event manager 7.4 -