CVE-2021-0146Medium· 6.8▾ SunlitHardware allows activation of test or debug logic at runtime for some Intel(R) processors which may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 37.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
Hardware allows activation of test or debug logic at runtime for some Intel(R) processors which may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
pentium_j6426_firmwarepentium_j4205_firmwarepentium_j3710_firmwarepentium_j2900_firmwarepentium_j2850_firmwareceleron_j6412_firmwareceleron_j6413_firmwareceleron_j4125_firmwareceleron_j4025_firmwareceleron_j3355e_firmwareceleron_j3455e_firmwareceleron_j4105_firmwareceleron_j4005_firmwareceleron_j3455_firmwareceleron_j3355_firmwareceleron_j3160_firmwareceleron_j3060_firmwareceleron_j1800_firmwareceleron_j1900_firmwareceleron_j1850_firmwareceleron_j1750_firmwareceleron_n6210_firmwareceleron_n4505_firmwareceleron_n4500_firmwareceleron_n5105_firmwareceleron_n5100_firmwareceleron_n6211_firmwareceleron_n4120_firmwareceleron_n4020_firmwareceleron_n3350e_firmwareceleron_n4000_firmwareceleron_n4100_firmwareceleron_n3350_firmwareceleron_n3450_firmwareceleron_n3060_firmwareceleron_n3160_firmwareceleron_n3010_firmwareceleron_n3000_firmwareceleron_n3050_firmwareceleron_n3150_firmwareceleron_n2808_firmwareceleron_n2840_firmwareceleron_n2940_firmwareceleron_n2807_firmwareceleron_n2830_firmwareceleron_n2930_firmwareceleron_n2806_firmwareceleron_n2920_firmwareceleron_n2820_firmwareceleron_n2815_firmwareceleron_n2805_firmwareceleron_n2810_firmwareceleron_n2910_firmwareatom_x5-e3930_firmwareatom_x5-e3940_firmwareatom_x7-e3950_firmwarepentium_n6415_firmwarepentium_n4200_firmwarepentium_n3710_firmwarepentium_n4200e_firmwarepentium_n3700_firmwarepentium_n3540_firmwarepentium_n3530_firmwarepentium_n3520_firmwarepentium_n3510_firmwarepentium_silver_n6005_firmwarepentium_silver_n6000_firmwarepentium_silver_j5040_firmwarepentium_silver_n5030_firmwarepentium_silver_j5005_firmwarepentium_silver_n5000_firmwareatom_c3000_firmwareRefer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2021-0114Medium· 6.7Unchecked return value in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access.
CVE-2021-0095Medium· 4.4Improper initialization in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable a denial of service via local access.
CVE-2020-12322Medium· 6.5Improper input validation in some Intel(R) Wireless Bluetooth(R) products before version 21.110 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
CVE-2020-12321High· 8.8Improper buffer restriction in some Intel(R) Wireless Bluetooth(R) products before version 21.110 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.
CVE-2020-24489High· 8.8Incomplete cleanup in some Intel(R) VT-d products may allow an authenticated user to potentially enable escalation of privilege via local access.
CVE-2020-24513Medium· 6.5Domain-bypass transient execution vulnerability in some Intel Atom(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.