8.8

CVE-2021-33115

Improper input validation for some Intel(R) PROSet/Wireless WiFi in UEFI may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Intel ≫ Uefi Wifi Driver Version < 1.2.8.21337
   Intel ≫ Ac 3165 Version -
   Intel ≫ Ac 3168 Version -
   Intel ≫ Ac 7265 Version -
   Intel ≫ Ac 8260 Version -
   Intel ≫ Ac 8265 Version -
   Intel ≫ Ac 9260 Version -
   Intel ≫ Ac 9461 Version -
   Intel ≫ Ac 9462 Version -
   Intel ≫ Ac 9560 Version -
   Intel ≫ Ax200 Version -
   Intel ≫ Ax201 Version -
   Intel ≫ Ax210 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.69% 0.483
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 5.8 6.5 6.4
AV:A/AC:L/Au:N/C:P/I:P/A:P
CISA-ADP 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00582.html
Vendor Advisory