Observable timing discrepancy in Intel(R) IPP before version 2020 update 1 may allow authorized user to potentially enable information disclosure via local access.
Conclusion & alert: CVE-2021-0001 is rated Low Risk (28.9/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.13%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-03-30 | 0.21% | 0.13% | -0.08% |
| 2 | 2025-03-29 | 0.13% | 0.21% | +0.08% |
| 3 | 2025-03-17 | — | 0.13% | — |
Full EPSS history (8 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 4.7 | 3.1 | MEDIUM |
|
1.0 | 3.6 | [email protected] |
| 2.1 | 2.0 | LOW |
|
3.9 | 2.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| intel | integrated_performance_primitives_cryptography | 2019 | cpe:2.3:a:intel:integrated_performance_primitives_cryptography:2019:-:*:*:*:*:*:* |
| intel | integrated_performance_primitives_cryptography | 2019 | cpe:2.3:a:intel:integrated_performance_primitives_cryptography:2019:update_1:*:*:*:*:*:* |
| intel | integrated_performance_primitives_cryptography | 2019 | cpe:2.3:a:intel:integrated_performance_primitives_cryptography:2019:update_2:*:*:*:*:*:* |
| intel | integrated_performance_primitives_cryptography | 2019 | cpe:2.3:a:intel:integrated_performance_primitives_cryptography:2019:update_3:*:*:*:*:*:* |
| intel | integrated_performance_primitives_cryptography | 2019 | cpe:2.3:a:intel:integrated_performance_primitives_cryptography:2019:update_4:*:*:*:*:*:* |
| intel | integrated_performance_primitives_cryptography | 2020 | cpe:2.3:a:intel:integrated_performance_primitives_cryptography:2020:-:*:*:*:*:*:* |
| intel | sgx_dcap | <= 1.10.100.4 | cpe:2.3:a:intel:sgx_dcap:*:*:*:*:*:linux:*:* |
| intel | sgx_dcap | <= 1.10.100.4 | cpe:2.3:a:intel:sgx_dcap:*:*:*:*:*:windows:*:* |
| intel | sgx_psw | <= 2.12.100.4 | cpe:2.3:a:intel:sgx_psw:*:*:*:*:*:windows:*:* |
| intel | sgx_psw | <= 2.13.100.4 | cpe:2.3:a:intel:sgx_psw:*:*:*:*:*:linux:*:* |
| intel | sgx_sdk | <= 2.12.100.4 | cpe:2.3:a:intel:sgx_sdk:*:*:*:*:*:windows:*:* |
| intel | sgx_sdk | <= 2.13.100.4 | cpe:2.3:a:intel:sgx_sdk:*:*:*:*:*:linux:*:* |
| URL | Tags |
|---|---|
| https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00477.html | Patch Vendor Advisory |