CVE-2021-33086

moderate-risk
Published 2021-11-17

Out-of-bounds write in firmware for some Intel(R) NUCs may allow an authenticated user to potentially enable denial of service via local access.

Do I need to act?

-
0.04% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
5
CVSS 5.5/10 Medium
LOCAL / LOW complexity

Affected Products (20)

Nuc M15 Laptop Kit Lapbc510 Firmware
Nuc M15 Laptop Kit Lapbc710 Firmware
Nuc 11 Compute Element Cm11Ebc4W Firmware
Nuc 11 Compute Element Cm11Ebi38W Firmware
Nuc 11 Compute Element Cm11Ebi58W Firmware
Nuc 11 Compute Element Cm11Ebi716W Firmware
Nuc 11 Performance Kit Nuc11Pahi3 Firmware
Nuc 11 Performance Kit Nuc11Pahi5 Firmware
Nuc 11 Performance Kit Nuc11Pahi7 Firmware
Nuc 11 Performance Kit Nuc11Paki3 Firmware
Nuc 11 Performance Kit Nuc11Paki5 Firmware
Nuc 11 Performance Kit Nuc11Paki7 Firmware
Nuc 11 Performance Mini Pc Nuc11Paqi50Wa Firmware
Nuc 11 Performance Mini Pc Nuc11Paqi70Qa Firmware
Nuc 11 Pro Board Nuc11Tnbi3 Firmware
Nuc 11 Pro Board Nuc11Tnbi5 Firmware
Nuc 11 Pro Board Nuc11Tnbi7 Firmware
Nuc 11 Pro Kit Nuc11Tnhi3 Firmware
Nuc 11 Pro Kit Nuc11Tnhi30L Firmware
Nuc 11 Pro Kit Nuc11Tnhi30P Firmware

Affected Vendors

48
/ 100
moderate-risk
Severity 18/34 · Moderate
Exploitability 0/34 · Minimal
Exposure 30/34 · Critical