CVE-2021-0146
6.8
MEDIUM
CVSS 3.1
EPSS 0.25%
Description
Hardware allows activation of test or debug logic at runtime for some Intel(R) processors which may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
How to fix CVE-2021-0146
To remediate CVE-2021-0146, upgrade the affected package to a fixed version below.
- Alpine/intel-ucode—upgrade to 20220207-r0 or later
Is CVE-2021-0146 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 20220207-r0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.8 | CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |