CVE-2021-33146

EUVD-2021-19861
Improper input validation in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow an unauthenticated user to potentially enable information disclosure via network access.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
intelethernet_controller_i225-it_firmware
𝑥
< 1.87
intelethernet_controller_i225-lm_firmware
𝑥
< 1.87
intelethernet_controller_i225-v_firmware
𝑥
< 1.87
intelethernet_adapter_complete_driver
𝑥
< 29.0.1
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
intelethernet_controller_i225_manageability_firmware
𝑥
< nvm_version_1.87
ADP
intelethernet_adapter
𝑥
< 29.0.1
ADP