CVE-2021-33080 describes a sensitive information exposure vulnerability in firmware for certain Intel SSD DC and Intel Optane SSD products. Debug information left uncleared in the firmware could allow an unauthenticated attacker with physical access to achieve information disclosure or escalation of privilege. This medium-severity vulnerability (CVSS 6.8) requires physical access, but once achieved, it is easy to exploit with high impact on confidentiality, integrity, and availability. There is no public exploit code available, nor is it known to be actively exploited, with minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< e2010600CPE matchmatch criteria | cpe:2.3:o:intel:optane_ssd_dc_p4800x_firmware:*:*:*:*:*:*:*:* | ||
< e2010600CPE matchmatch criteria | cpe:2.3:o:intel:optane_ssd_dc_p4801x_firmware:*:*:*:*:*:*:*:* | ||
< l0310200CPE matchmatch criteria | cpe:2.3:o:intel:optane_ssd_p5800x_firmware:*:*:*:*:*:*:*:* | ||
< pgf028kCPE matchmatch criteria | cpe:2.3:o:intel:optane_memory_h20_with_solid_state_storage_firmware:*:*:*:*:*:*:*:* | ||
< tgf061kCPE matchmatch criteria | cpe:2.3:o:intel:optane_memory_h10_with_solid_state_storage_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.