« Volver al listado

CVE-2021-0001

Estado: ModificadaMedia (4.7)—

Observable timing discrepancy in Intel(R) IPP before version 2020 update 1 may allow authorized user to potentially enable information disclosure via local access.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (4)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-0001",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 2.1,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.7,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1
      }
    ]
  },
  "affected": [
    {
      "source": "secure@intel.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "Intel(R) IPP",
          "versions": [
            {
              "status": "affected",
              "version": "before version 2020 update 1"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-06-09T20:15:08.180",
  "references": [
    {
      "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00477.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "secure@intel.com"
    },
    {
      "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00477.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-203"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Observable timing discrepancy in Intel(R) IPP before version 2020 update 1 may allow authorized user to potentially enable information disclosure via local access."
    },
    {
      "lang": "es",
      "value": "Una discrepancia de tiempo observable en Intel® IPP versiones anteriores a 2020 update 1, puede permitir a un usuario autorizado permitir potencialmente una divulgación de información por medio de un acceso local"
    }
  ],
  "lastModified": "2026-06-17T03:28:57.230",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:intel:integrated_performance_primitives_cryptography:2019:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C228B092-D84F-4A92-B9A7-C85E069ACE04"
            },
            {
              "criteria": "cpe:2.3:a:intel:integrated_performance_primitives_cryptography:2019:update_1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1D59D26E-C3A9-425D-BF47-9F100406B55C"
            },
            {
              "criteria": "cpe:2.3:a:intel:integrated_performance_primitives_cryptography:2019:update_2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A5E59DAE-EDD5-41E2-81EB-68CCEE6111C4"
            },
            {
              "criteria": "cpe:2.3:a:intel:integrated_performance_primitives_cryptography:2019:update_3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "43B76D8D-6BF9-4468-896B-C41E777E2B19"
            },
            {
              "criteria": "cpe:2.3:a:intel:integrated_performance_primitives_cryptography:2019:update_4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "46B03979-727A-4230-8B35-7BC9F4C24D7C"
            },
            {
              "criteria": "cpe:2.3:a:intel:integrated_performance_primitives_cryptography:2020:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6FCBAD61-98CA-4FC4-B748-E2367EF8D4C4"
            },
            {
              "criteria": "cpe:2.3:a:intel:sgx_dcap:*:*:*:*:*:linux:*:*",
              "vulnerable": true,
              "matchCriteriaId": "051C831D-C8FB-41F5-B2B9-152C7B7FE66D",
              "versionEndIncluding": "1.10.100.4"
            },
            {
              "criteria": "cpe:2.3:a:intel:sgx_dcap:*:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7D87FA8C-54D8-4C79-9A46-59563B6A1B05",
              "versionEndIncluding": "1.10.100.4"
            },
            {
              "criteria": "cpe:2.3:a:intel:sgx_psw:*:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0347067C-4AEC-4F6A-B35B-21671FC553F4",
              "versionEndIncluding": "2.12.100.4"
            },
            {
              "criteria": "cpe:2.3:a:intel:sgx_psw:*:*:*:*:*:linux:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6BEB7E68-4C75-42E4-AF30-4643CF166F70",
              "versionEndIncluding": "2.13.100.4"
            },
            {
              "criteria": "cpe:2.3:a:intel:sgx_sdk:*:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B5717416-A859-45C8-BBF1-F33AF80536B3",
              "versionEndIncluding": "2.12.100.4"
            },
            {
              "criteria": "cpe:2.3:a:intel:sgx_sdk:*:*:*:*:*:linux:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3643652F-9986-48AB-A479-91BC7AFB2847",
              "versionEndIncluding": "2.13.100.4"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secure@intel.com"
}