CVE-2021-33123 describes an improper access control vulnerability in the BIOS authenticated code module of certain Intel Processors. This flaw allows a privileged local user to potentially escalate privileges. With a CVSS score of 7.8 (High), it presents a significant risk, enabling high impact to confidentiality, integrity, and availability with low attack complexity. Currently, there is no evidence of active exploitation, nor is public exploit code available, and it is not listed on CISA's KEV catalog. Community discussion and media coverage are minimal, suggesting limited public awareness or active threat intelligence surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:intel:xeon_bronze_3206r_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:intel:xeon_gold_5218r_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:intel:xeon_gold_5220r_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:intel:xeon_gold_6208u_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:intel:xeon_gold_6226r_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.