SB2022020924 - Insufficiently protected credentials in Intel AMT SDK, SCS and MEBx
Published: February 9, 2022
Security Bulletin ID
SB2022020924
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Physical access
Highest impact
Code execution
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Insufficiently protected credentials (CVE-ID: CVE-2021-33107)
The vulnerability allows a local attacker to compromise the target system.
The vulnerability exists due to insufficiently protected credentials in USB provisioning. An attacker with physical access can obtain credentials and gain elevated privileges on the system.
Remediation
Install update from vendor's website.