Insufficient Compartmentalization in Intel SPS Subsystem
CVE-2021-0060

6.6MEDIUM

Key Information:

Vendor
Intel
Vendor
CVE Published:
9 February 2022

Summary

The HECI subsystem for Intel Server Platform Services has a vulnerability stemming from insufficient compartmentalization. This flaw may enable an authenticated user with physical access to the hardware to potentially escalate their privileges. Certain versions of the SPS are affected, and users are encouraged to review the official advisories for mitigation strategies.

Affected Version(s)

Intel(R) SPS see references

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.