ID

VAR-202111-1619


CVE

CVE-2021-33058


TITLE

Windows  for  Intel(R) Administrative Tools for Intel(R) Network Adapters  Vulnerability in

Trust: 0.8

sources: JVNDB: JVNDB-2021-015264

DESCRIPTION

Improper access control in the installer Intel(R)Administrative Tools for Intel(R) Network Adaptersfor Windowsbefore version 1.4.0.21 may allow an unauthenticated user to potentially enable escalation of privilege via local access. Windows for Intel(R) Administrative Tools for Intel(R) Network Adapters Exists in unspecified vulnerabilities.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. Intel Ethernet Controllers is an Ethernet controller of Intel Corporation of the United States

Trust: 1.71

sources: NVD: CVE-2021-33058 // JVNDB: JVNDB-2021-015264 // VULHUB: VHN-393072

AFFECTED PRODUCTS

vendor:intelmodel:administrative tools for intel network adaptersscope:ltversion:1.4.0.21

Trust: 1.0

vendor:インテルmodel:administrative tools for intel network adaptersscope:eqversion:1.4.0.21

Trust: 0.8

vendor:インテルmodel:administrative tools for intel network adaptersscope:eqversion: -

Trust: 0.8

sources: JVNDB: JVNDB-2021-015264 // NVD: CVE-2021-33058

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2021-33058
value: HIGH

Trust: 1.0

NVD: CVE-2021-33058
value: HIGH

Trust: 0.8

CNNVD: CNNVD-202111-921
value: HIGH

Trust: 0.6

VULHUB: VHN-393072
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2021-33058
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-393072
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2021-33058
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.1

Trust: 1.0

NVD: CVE-2021-33058
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULHUB: VHN-393072 // JVNDB: JVNDB-2021-015264 // CNNVD: CNNVD-202111-921 // NVD: CVE-2021-33058

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

problemtype:others (CWE-Other) [NVD evaluation ]

Trust: 0.8

problemtype:CWE-863

Trust: 0.1

sources: VULHUB: VHN-393072 // JVNDB: JVNDB-2021-015264 // NVD: CVE-2021-33058

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-202111-921

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202111-921

PATCH

title:INTEL-SA-00555url:https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00555.html

Trust: 0.8

title:Intel Ethernet controllers Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=170926

Trust: 0.6

sources: JVNDB: JVNDB-2021-015264 // CNNVD: CNNVD-202111-921

EXTERNAL IDS

db:NVDid:CVE-2021-33058

Trust: 3.3

db:JVNid:JVNVU91196719

Trust: 0.8

db:JVNDBid:JVNDB-2021-015264

Trust: 0.8

db:CNNVDid:CNNVD-202111-921

Trust: 0.7

db:LENOVOid:LEN-66618

Trust: 0.6

db:AUSCERTid:ESB-2021.3729

Trust: 0.6

db:VULHUBid:VHN-393072

Trust: 0.1

sources: VULHUB: VHN-393072 // JVNDB: JVNDB-2021-015264 // CNNVD: CNNVD-202111-921 // NVD: CVE-2021-33058

REFERENCES

url:https://security.netapp.com/advisory/ntap-20211210-0005/

Trust: 1.7

url:https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00555.html

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2021-33058

Trust: 1.4

url:https://jvn.jp/vu/jvnvu91196719/

Trust: 0.8

url:https://vigilance.fr/vulnerability/intel-ethernet-drivers-three-vulnerabilities-37224

Trust: 0.6

url:https://support.lenovo.com/us/en/product_security/len-66618

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2021.3729

Trust: 0.6

sources: VULHUB: VHN-393072 // JVNDB: JVNDB-2021-015264 // CNNVD: CNNVD-202111-921 // NVD: CVE-2021-33058

SOURCES

db:VULHUBid:VHN-393072
db:JVNDBid:JVNDB-2021-015264
db:CNNVDid:CNNVD-202111-921
db:NVDid:CVE-2021-33058

LAST UPDATE DATE

2024-08-14T12:31:42.450000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-393072date:2022-06-28T00:00:00
db:JVNDBid:JVNDB-2021-015264date:2022-11-15T01:46:00
db:CNNVDid:CNNVD-202111-921date:2022-06-30T00:00:00
db:NVDid:CVE-2021-33058date:2022-06-28T14:11:45.273

SOURCES RELEASE DATE

db:VULHUBid:VHN-393072date:2021-11-17T00:00:00
db:JVNDBid:JVNDB-2021-015264date:2022-11-15T00:00:00
db:CNNVDid:CNNVD-202111-921date:2021-11-10T00:00:00
db:NVDid:CVE-2021-33058date:2021-11-17T20:15:09.793