SB2022020924 - Insufficiently protected credentials in Intel AMT SDK, SCS and MEBx 



SB2022020924 - Insufficiently protected credentials in Intel AMT SDK, SCS and MEBx

Published: February 9, 2022

Security Bulletin ID SB2022020924
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Physical access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Insufficiently protected credentials (CVE-ID: CVE-2021-33107)

The vulnerability allows a local attacker to compromise the target system.

The vulnerability exists due to insufficiently protected credentials in USB provisioning. An attacker with physical access can obtain credentials and gain elevated privileges on the system.


Remediation

Install update from vendor's website.