CVE-2021-37409

Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow a privileged user to potentially enable escalation of privilege via local access.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
intelCNA
---
---
CVEADP
---
---
CISA-ADPADP
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 20%
VendorProductVersion
intelwireless-ac_9560_firmware
𝑥
< 22.120
intelwireless-ac_9462_firmware
𝑥
< 22.120
intelwireless-ac_9461_firmware
𝑥
< 22.120
intelkiller_ac_1550_firmware
𝑥
< 3.1122.1105
intelkiller_wi-fi_6_ax1650_firmware
𝑥
< 3.1122.1105
intelkiller_wi-fi_6e_ax1690_firmware
𝑥
< 3.1122.1105
intelkiller_wi-fi_6e_ax1675_firmware
𝑥
< 3.1122.1105
intelwireless-ac_9260_firmware
𝑥
< 22.120
intelproset_wi-fi_6e_ax210_firmware
𝑥
< 22.120
intelwi-fi_6e_ax211_firmware
𝑥
< 22.120
intelwi-fi_6_ax200_firmware
𝑥
< 22.120
intelwi-fi_6_ax201_firmware
𝑥
< 22.120
intelwi-fi_6e_ax411_firmware
𝑥
< 22.120
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
firmware-nonfree
bullseye/non-free
vulnerable
bookworm/non-free-firmware
20230210-5
fixed
bullseye
no-dsa
sid/non-free-firmware
20240909-2
fixed
trixie/non-free-firmware
20240909-2
fixed