Xeon E 2336 Firmware
Vendor:
First CVE: Feb 9, 2022 · Active for 4 years
23
Total CVEs
More Total CVEs than 96% of tracked products
11.5
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Xeon E 2336 Firmware over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 9, 2022
4 years ago
Most Recent CVE
Aug 11, 2023
1,082 days ago
CVE Severity & Scoring
Xeon E 2336 Firmware23 CVEs
52%
43%
All CVEs353,173 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local18 (78.3%)
Network0 (0.0%)
Unknown0 (0.0%)
Physical4 (17.4%)
Adjacent Network1 (4.3%)
Attack Complexity
Low22 (95.7%)
High1 (4.3%)
Unknown0 (0.0%)
User Interaction
None23 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low17 (73.9%)
High5 (21.7%)
None1 (4.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-0154HIGH Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access. | May 12, 2022 | 7.8 | 26 | NO | NO |
CVE-2021-0189HIGH Use of out-of-range pointer offset in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access. | May 12, 2022 | 7.8 | 25 | NO | NO |
CVE-2021-0156HIGH Improper input validation in the firmware for some Intel(R) Processors may allow an authenticated user to potentially enable an escalation of privilege via local access. | Feb 9, 2022 | 7.8 | 25 | NO | NO |
CVE-2021-0116HIGH Out-of-bounds write in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access. | Feb 9, 2022 | 7.8 | 25 | NO | NO |
CVE-2022-40982MEDIUM Information exposure through microarchitectural state after transient execution in certain vector execution units for some Intel(R) Processors may allow an authenticated user to po | Aug 11, 2023 | 6.5 | 24 | NO | NO |
CVE-2022-33894HIGH Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. | May 10, 2023 | 7.8 | 24 | NO | NO |
CVE-2021-33123HIGH Improper access control in the BIOS authenticated code module for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local acce | May 12, 2022 | 7.8 | 24 | NO | NO |
CVE-2021-33122HIGH Insufficient control flow management in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access. | May 12, 2022 | 7.8 | 24 | NO | NO |
CVE-2021-0118MEDIUM Out-of-bounds read in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access. | Feb 9, 2022 | 6.7 | 23 | NO | NO |
CVE-2022-26837HIGH Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. | Feb 16, 2023 | 7.0 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (23 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (23 CVEs).
Media Mentions
Signals from CVEs in this product scope (23 CVEs).
Top CNAs Publishing CVEs For Xeon E 2336 Firmware
Top CWEs
Versions
No cataloged versions.