Information Disclosure via Debug Info in Intel SSDs and Optane Products
CVE-2021-33080
6.8MEDIUM
Key Information:
- Vendor
- Intel
- Vendor
- CVE Published:
- 12 May 2022
Summary
The vulnerability arises from the presence of uncleared debug information in the firmware of specific Intel storage products. This flaw may permit an unauthenticated user with physical access to the device to exploit the information leak, which could lead to unauthorized access to sensitive system data or potential privilege escalation. This risk emphasizes the critical need for securing physical access to hardware and properly managing debug information in firmware.
Affected Version(s)
Intel(R) SSD DC, Intel(R) Optane(TM) SSD and Intel(R) Optane(TM) SSD DC Products See references
References
CVSS V3.1
Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved