CVE-2021-0071

Improper input validation in firmware for some Intel(R) PROSet/Wireless WiFi in UEFI may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 44%
Affected Products (NVD)
VendorProductVersion
intelax210_firmware
𝑥
< 22.40
intelax201_firmware
𝑥
< 22.40
intelax200_firmware
𝑥
< 22.40
intelac_9560_firmware
𝑥
< 22.40
intelac_9462_firmware
𝑥
< 22.40
intelac_9461_firmware
𝑥
< 22.40
intel9260_firmware
-
intelac_9260_firmware
𝑥
< 22.40
intelac_8265_firmware
𝑥
< 22.40
intelac_8260_firmware
𝑥
< 22.40
intelac_3168_firmware
𝑥
< 22.40
intel7265_firmware
𝑥
< 22.40
intelac_3165_firmware
𝑥
< 22.40
𝑥
= Vulnerable software versions
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
kernel-firmware-20200107
suse enterprise sap 15 SP1
150100.3.31.1
fixed
suse enterprise sap 15 SP2
150100.3.31.1
fixed
suse enterprise server 15 SP1
150100.3.31.1
fixed
suse enterprise server 15 SP2
150100.3.31.1
fixed
kernel-firmware-20210208
suse enterprise desktop 15 SP3
150300.4.7.1
fixed
suse enterprise sap 15 SP3
150300.4.7.1
fixed
suse enterprise server 15 SP3
150300.4.7.1
fixed
kernel-firmware-brcm-20210208
suse enterprise desktop 15 SP3
150300.4.7.1
fixed
suse enterprise sap 15 SP3
150300.4.7.1
fixed
suse enterprise server 15 SP3
150300.4.7.1
fixed
ucode-amd-20200107
suse enterprise sap 15 SP1
150100.3.31.1
fixed
suse enterprise sap 15 SP2
150100.3.31.1
fixed
suse enterprise server 15 SP1
150100.3.31.1
fixed
suse enterprise server 15 SP2
150100.3.31.1
fixed
ucode-amd-20210208
suse enterprise desktop 15 SP3
150300.4.7.1
fixed
suse enterprise sap 15 SP3
150300.4.7.1
fixed
suse enterprise server 15 SP3
150300.4.7.1
fixed