Exposure of sensitive system information due to uncleared debug information in firmware for some Intel(R) SSD DC, Intel(R) Optane(TM) SSD and Intel(R) Optane(TM) SSD DC Products may allow an unauthenticated user to potentially enable information disclosure or escalation of privilege via physical access.
References
Link | Resource |
---|---|
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00563.html | Mitigation Vendor Advisory |
https://www.solidigm.com/content/dam/newco-aem-site/master/site/support/Solidigm%20SA-000563%20rev1.1.pdf | Broken Link |
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00563.html | Mitigation Vendor Advisory |
https://www.solidigm.com/content/dam/newco-aem-site/master/site/support/Solidigm%20SA-000563%20rev1.1.pdf | Broken Link |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
History
21 Nov 2024, 06:08
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00563.html - Mitigation, Vendor Advisory | |
References | () https://www.solidigm.com/content/dam/newco-aem-site/master/site/support/Solidigm%20SA-000563%20rev1.1.pdf - Broken Link |
Information
Published : 2022-05-12 17:15
Updated : 2024-11-21 06:08
NVD link : CVE-2021-33080
Mitre link : CVE-2021-33080
CVE.ORG link : CVE-2021-33080
JSON object : View
Products Affected
intel
- optane_ssd_900p_firmware
- optane_ssd_dc_p4800x_firmware
- optane_ssd_dc_p4801x_firmware
- optane_memory_h10_with_solid_state_storage
- optane_ssd_900p
- optane_ssd_p5800x_firmware
- optane_memory_h20_with_solid_state_storage
- optane_memory_h10_with_solid_state_storage_firmware
- optane_memory_h20_with_solid_state_storage_firmware
- optane_ssd_dc_p4800x
- optane_ssd_dc_p4801x
- optane_ssd_905p_firmware
- optane_ssd_905p
- optane_ssd_p5800x
CWE
CWE-212
Improper Removal of Sensitive Information Before Storage or Transfer