CVE-2021-33162

Severity CVSS v4.0:
Pending analysis
Type:
CWE-284 Improper Access Control
Publication date:
23/02/2024
Last modified:
09/01/2026

Description

Improper access control in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow an authenticated user to potentially enable escalation of privilege via local access.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:intel:ethernet_controller_i225-it_firmware:*:*:*:*:*:*:*:* 1.87 (excluding)
cpe:2.3:h:intel:ethernet_controller_i225-it:-:*:*:*:*:*:*:*
cpe:2.3:o:intel:ethernet_controller_i225-lm_firmware:*:*:*:*:*:*:*:* 1.87 (excluding)
cpe:2.3:h:intel:ethernet_controller_i225-lm:-:*:*:*:*:*:*:*
cpe:2.3:o:intel:ethernet_controller_i225-v_firmware:*:*:*:*:*:*:*:* 1.87 (excluding)
cpe:2.3:h:intel:ethernet_controller_i225-v:-:*:*:*:*:*:*:*
cpe:2.3:a:intel:ethernet_adapter_complete_driver:*:*:*:*:*:*:*:* 29.0.1 (excluding)