VYPR

Fas\/aff BIOS

by NetApp

CVEs (22)

  • CVE-2021-0156HigFeb 9, 2022
    risk 0.51cvss 7.8epss 0.00

    Improper input validation in the firmware for some Intel(R) Processors may allow an authenticated user to potentially enable an escalation of privilege via local access.

  • CVE-2021-0117HigFeb 9, 2022
    risk 0.51cvss 7.8epss 0.00

    Pointer issues in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access.

  • CVE-2021-0116HigFeb 9, 2022
    risk 0.51cvss 7.8epss 0.00

    Out-of-bounds write in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access.

  • CVE-2021-0099HigFeb 9, 2022
    risk 0.51cvss 7.8epss 0.00

    Insufficient control flow management in the firmware for some Intel(R) Processors may allow an authenticated user to potentially enable an escalation of privilege via local access.

  • CVE-2021-0091HigFeb 9, 2022
    risk 0.51cvss 7.8epss 0.00

    Improper access control in the firmware for some Intel(R) Processors may allow an unauthenticated user to potentially enable an escalation of privilege via local access.

  • CVE-2020-0590HigNov 12, 2020
    risk 0.51cvss 7.8epss 0.00

    Improper input validation in BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2021-33625HigFeb 3, 2022
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in Kernel 5.x in Insyde InsydeH2O, affecting HddPassword. Software SMI services that use the Communicate() function of the EFI_SMM_COMMUNICATION_PROTOCOL do not check whether the address of the buffer is valid, which allows use of SMRAM, MMIO, or OS…

  • CVE-2021-0118MedFeb 9, 2022
    risk 0.44cvss 6.7epss 0.00

    Out-of-bounds read in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access.

  • CVE-2021-0115MedFeb 9, 2022
    risk 0.44cvss 6.7epss 0.00

    Buffer overflow in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2021-0111MedFeb 9, 2022
    risk 0.44cvss 6.7epss 0.00

    NULL pointer dereference in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access.

  • CVE-2021-0107MedFeb 9, 2022
    risk 0.44cvss 6.7epss 0.00

    Unchecked return value in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2021-0103MedFeb 9, 2022
    risk 0.44cvss 6.7epss 0.00

    Insufficient control flow management in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access.

  • CVE-2020-8738MedNov 12, 2020
    risk 0.44cvss 6.7epss 0.00

    Improper conditions check in Intel BIOS platform sample code for some Intel(R) Processors before may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2021-0125MedFeb 9, 2022
    risk 0.43cvss 6.6epss 0.00

    Improper initialization in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via physical access.

  • CVE-2021-0124MedFeb 9, 2022
    risk 0.43cvss 6.6epss 0.00

    Improper access control in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via physical access.

  • CVE-2020-24511MedJun 9, 2021
    risk 0.42cvss 6.5epss 0.00

    Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2021-0119MedFeb 9, 2022
    risk 0.40cvss 6.2epss 0.00

    Improper initialization in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via physical access.

  • CVE-2021-33117MedMay 12, 2022
    risk 0.36cvss 5.5epss 0.00

    Improper access control for some 3rd Generation Intel(R) Xeon(R) Scalable Processors before BIOS version MR7, may allow a local attacker to potentially enable information disclosure via local access.

  • CVE-2021-0145MedFeb 9, 2022
    risk 0.36cvss 5.5epss 0.00

    Improper initialization of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2021-0093MedFeb 9, 2022
    risk 0.29cvss 4.4epss 0.00

    Incorrect default permissions in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable a denial of service via local access.

Page 1 of 2