ZeroHour

CVE-2021-0060

CVSS 3.1
6.6 medium
EPSS
<1%p25
Published
()
Modified
Description

Insufficient compartmentalization in HECI subsystem for the Intel(R) SPS before versions SPS_E5_04.01.04.516.0, SPS_E5_04.04.04.033.0, SPS_E5_04.04.03.281.0, SPS_E5_03.01.03.116.0, SPS_E3_05.01.04.309.0, SPS_02.04.00.101.0, SPS_SoC-A_05.00.03.114.0, SPS_SoC-X_04.00.04.326.0, SPS_SoC-X_03.00.03.117.0, IGN_E5_91.00.00.167.0, SPS_PHI_03.01.03.078.0 may allow an authenticated user to potentially enable escalation of privilege via physical access.

Vendors
intelnetapp
Products
c620a series firmware, c620 series firmware, c240 series firmware, atom p5000 series firmware, atom c3000 series firmware, atom c610 series firmware, xeon d-1500 series firmware, xeon d 2000 series firmware, 11th generation core series firmware, xeon w-1300 series firmware, pentium gold series firmware, celeron 6000 series firmware
Vector
CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.