NA

CVE-2022-21216

Published: 16/02/2023 Updated: 08/08/2023
CVSS v3 Base Score: 6.8 | Impact Score: 5.9 | Exploitability Score: 0.9
VMScore: 0

Vulnerability Summary

Insufficient granularity of access control in out-of-band management in some Intel(R) Atom and Intel Xeon Scalable Processors may allow a privileged user to potentially enable escalation of privilege via adjacent network access.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

intel xeon_gold_5315y_firmware -

intel xeon_gold_5317_firmware -

intel xeon_gold_5318n_firmware -

intel xeon_gold_5318s_firmware -

intel xeon_gold_5318y_firmware -

intel xeon_gold_5320_firmware -

intel xeon_gold_5320t_firmware -

intel xeon_gold_6312u_firmware -

intel xeon_gold_6314u_firmware -

intel xeon_gold_6326_firmware -

intel xeon_gold_6330_firmware -

intel xeon_gold_6330n_firmware -

intel xeon_gold_6334_firmware -

intel xeon_gold_6336y_firmware -

intel xeon_gold_6338_firmware -

intel xeon_gold_6338n_firmware -

intel xeon_gold_6338t_firmware -

intel xeon_gold_6342_firmware -

intel xeon_gold_6346_firmware -

intel xeon_gold_6348_firmware -

intel xeon_gold_6354_firmware -

intel xeon_platinum_8351n_firmware -

intel xeon_platinum_8352m_firmware -

intel xeon_platinum_8352s_firmware -

intel xeon_platinum_8352v_firmware -

intel xeon_platinum_8352y_firmware -

intel xeon_platinum_8358_firmware -

intel xeon_platinum_8358p_firmware -

intel xeon_platinum_8360y_firmware -

intel xeon_platinum_8362_firmware -

intel xeon_platinum_8368_firmware -

intel xeon_platinum_8368q_firmware -

intel xeon_platinum_8380_firmware -

intel xeon_silver_4309y_firmware -

intel xeon_silver_4310_firmware -

intel xeon_silver_4310t_firmware -

intel xeon_silver_4314_firmware -

intel xeon_silver_4316_firmware -

intel xeon_gold_6330h_firmware -

intel xeon_platinum_8356h_firmware -

intel xeon_platinum_8360h_firmware -

intel xeon_platinum_8360hl_firmware -

intel xeon_gold_5318h_firmware -

intel xeon_gold_5320h_firmware -

intel xeon_gold_6328h_firmware -

intel xeon_gold_6328hl_firmware -

intel xeon_gold_6348h_firmware -

intel xeon_platinum_8353h_firmware -

intel xeon_platinum_8354h_firmware -

intel xeon_platinum_8376h_firmware -

intel xeon_platinum_8376hl_firmware -

intel xeon_platinum_8380h_firmware -

intel xeon_platinum_8380hl_firmware -

intel atom_p5962b_firmware -

intel atom_p5942b_firmware -

intel atom_p5931b_firmware -

intel atom_p5921b_firmware -

intel atom_p5362_firmware -

intel atom_p5352_firmware -

intel atom_p5342_firmware -

intel atom_p5332_firmware -

intel atom_p5322_firmware -

intel atom_c5325_firmware -

intel atom_c5320_firmware -

intel atom_c5315_firmware -

intel atom_c5310_firmware -

Vendor Advisories

Debian Bug report logs - #1031334 intel-microcode: CVE-2022-21216 CVE-2022-33972 CVE-2022-33196 CVE-2022-38090 Package: src:intel-microcode; Maintainer for src:intel-microcode is Henrique de Moraes Holschuh <hmh@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 15 Feb 2023 07:54:01 UTC Sev ...
Insufficient granularity of access control in out-of-band management in some Intel(R) Atom and Intel Xeon Scalable Processors may allow a privileged user to potentially enable escalation of privilege via adjacent network access (CVE-2022-21216) Incorrect calculation in microcode keying mechanism for some 3rd Generation Intel(R) Xeon(R) Scalable Pr ...
Description<!---->A flaw was found in the Linux kernel A potential security vulnerability in some Intel(R) Atom(R) and Intel(R) Xeon(R) Scalable Processors may allow privilege escalation This flaw may allow a privileged user to enable privilege escalation via adjacent network accessA flaw was found in the Linux kernel A potential security vulne ...

Recent Articles

Intel patches up SGX best it can after another load of security holes found
The Register

Topics Security Off-Prem On-Prem Software Offbeat Vendor Voice Vendor Voice Resources Plus bugs squashed in Server Platform Services and more APIC fail: Intel 'Sunny Cove' chips with SGX spill secrets

Intel's Software Guard Extensions (SGX) are under the spotlight again after the chipmaker disclosed several newly discovered vulnerabilities affecting the tech, and recommended users update their firmware. The security holes are among the latest disclosures listed on Intel's Security Center page. These cover a wide range of Intel products including Xeon processors, network adapters, and also software. Overall, there were 31 advisories added to the Intel Security Center as of February 14, as we n...