CVE-2021-0154 describes an improper input validation vulnerability within the BIOS firmware of certain Intel Processors. This flaw could allow a privileged local user to escalate privileges. With a CVSS score of 7.8 (High), the vulnerability has a low attack complexity and requires local access and low privileges, but can lead to high impacts on confidentiality, integrity, and availability. There is no evidence of active exploitation, nor are there public exploit codes available in Metasploit, Nuclei, or ExploitDB, and it is not listed in CISA's KEV catalog. Community discussion and media coverage are minimal, with only one article from SecurityWeek.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:intel:xeon_e-2314_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:intel:xeon_e-2324g_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:intel:xeon_e-2334_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:intel:xeon_e-2336_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:intel:xeon_e-2356g_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.