CVE-2021-33107

Insufficiently protected credentials in USB provisioning for Intel(R) AMT SDK before version 16.0.3, Intel(R) SCS before version 12.2 and Intel(R) MEBx before versions 11.0.0.0012, 12.0.0.0011, 14.0.0.0004 and 15.0.0.0004 may allow an unauthenticated user to potentially enable information disclosure via physical access.

Published: 2022-02-09 Last update: 2026-06-16 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2021-33107 is rated Low Risk (24/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.25%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2021-33107

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 0.14% 0.25% +0.10%
2 2025-05-25 0.15% 0.14% -0.01%
3 2025-05-24 0.15%

Full EPSS history (9 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2021-33107

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
4.6 3.1 MEDIUM
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Click to expand
Attack vector (AV:P)
Hands-on access—USB, keyboard, opening the case—not something you do purely over the wire.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:N)
Data isn’t meaningfully altered or forged.
Availability (A:N)
Service keeps running; no real outage angle.
0.9 3.6 [email protected]
4.6 3.1 MEDIUM
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Click to expand
Attack vector (AV:P)
Hands-on access—USB, keyboard, opening the case—not something you do purely over the wire.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:N)
Data isn’t meaningfully altered or forged.
Availability (A:N)
Service keeps running; no real outage angle.
0.9 3.6 134c704f-9b21-4f2e-91b3-4a467353bcc0
2.1 2.0 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N Click to expand
Access vector (AV:L)
Requires local access to the target system.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:N)
No integrity impact.
Availability impact (A:N)
No availability impact.
3.9 2.9 [email protected]

Weakness enumeration for CVE-2021-33107

Affected software / configurations for CVE-2021-33107

Vendor Product Version Raw CPE
intel active_management_technology_software_development_kit < 16.0.3 cpe:2.3:a:intel:active_management_technology_software_development_kit:*:*:*:*:*:*:*:*
intel setup_and_configuration_software < 12.2 cpe:2.3:a:intel:setup_and_configuration_software:*:*:*:*:*:*:*:*
intel management_engine_bios_extension < 15.0.0.0004 cpe:2.3:a:intel:management_engine_bios_extension:*:*:*:*:*:*:*:*
intel management_engine_bios_extension < 14.0.0.0004 cpe:2.3:a:intel:management_engine_bios_extension:*:*:*:*:*:*:*:*
intel management_engine_bios_extension < 12.0.0.0011 cpe:2.3:a:intel:management_engine_bios_extension:*:*:*:*:*:*:*:*
intel management_engine_bios_extension < 11.0.0.0012 cpe:2.3:a:intel:management_engine_bios_extension:*:*:*:*:*:*:*:*
intel core_i3_firmware cpe:2.3:o:intel:core_i3_firmware:-:*:*:*:*:*:*:*
intel core_i3-1000g1_firmware cpe:2.3:o:intel:core_i3-1000g1_firmware:-:*:*:*:*:*:*:*
intel core_i3-1000g4_firmware cpe:2.3:o:intel:core_i3-1000g4_firmware:-:*:*:*:*:*:*:*
intel core_i3-1000ng4_firmware cpe:2.3:o:intel:core_i3-1000ng4_firmware:-:*:*:*:*:*:*:*
intel core_i3-1005g1_firmware cpe:2.3:o:intel:core_i3-1005g1_firmware:-:*:*:*:*:*:*:*
intel core_i3-10100_firmware cpe:2.3:o:intel:core_i3-10100_firmware:-:*:*:*:*:*:*:*
intel core_i3-10100e_firmware cpe:2.3:o:intel:core_i3-10100e_firmware:-:*:*:*:*:*:*:*
intel core_i3-10100f_firmware cpe:2.3:o:intel:core_i3-10100f_firmware:-:*:*:*:*:*:*:*
intel core_i3-10100t_firmware cpe:2.3:o:intel:core_i3-10100t_firmware:-:*:*:*:*:*:*:*
intel core_i3-10100te_firmware cpe:2.3:o:intel:core_i3-10100te_firmware:-:*:*:*:*:*:*:*
intel core_i3-10100y_firmware cpe:2.3:o:intel:core_i3-10100y_firmware:-:*:*:*:*:*:*:*
intel core_i3-10105_firmware cpe:2.3:o:intel:core_i3-10105_firmware:-:*:*:*:*:*:*:*
intel core_i3-10105f_firmware cpe:2.3:o:intel:core_i3-10105f_firmware:-:*:*:*:*:*:*:*
intel core_i3-10105t_firmware cpe:2.3:o:intel:core_i3-10105t_firmware:-:*:*:*:*:*:*:*
intel core_i3-10110u_firmware cpe:2.3:o:intel:core_i3-10110u_firmware:-:*:*:*:*:*:*:*
intel core_i3-10110y_firmware cpe:2.3:o:intel:core_i3-10110y_firmware:-:*:*:*:*:*:*:*
intel core_i3-10300_firmware cpe:2.3:o:intel:core_i3-10300_firmware:-:*:*:*:*:*:*:*
intel core_i3-10300t_firmware cpe:2.3:o:intel:core_i3-10300t_firmware:-:*:*:*:*:*:*:*
intel core_i3-10305_firmware cpe:2.3:o:intel:core_i3-10305_firmware:-:*:*:*:*:*:*:*
intel core_i3-10305t_firmware cpe:2.3:o:intel:core_i3-10305t_firmware:-:*:*:*:*:*:*:*
intel core_i3-10320_firmware cpe:2.3:o:intel:core_i3-10320_firmware:-:*:*:*:*:*:*:*
intel core_i3-10325_firmware cpe:2.3:o:intel:core_i3-10325_firmware:-:*:*:*:*:*:*:*
intel core_i3_8100_firmware cpe:2.3:o:intel:core_i3_8100_firmware:-:*:*:*:*:*:*:*
intel core_i3_8100f_firmware cpe:2.3:o:intel:core_i3_8100f_firmware:-:*:*:*:*:*:*:*
intel core_i3_8100t_firmware cpe:2.3:o:intel:core_i3_8100t_firmware:-:*:*:*:*:*:*:*
intel core_i3_8300_firmware cpe:2.3:o:intel:core_i3_8300_firmware:-:*:*:*:*:*:*:*
intel core_i3_8300t_firmware cpe:2.3:o:intel:core_i3_8300t_firmware:-:*:*:*:*:*:*:*
intel core_i3_8350k_firmware cpe:2.3:o:intel:core_i3_8350k_firmware:-:*:*:*:*:*:*:*
intel core_i3_9100_firmware cpe:2.3:o:intel:core_i3_9100_firmware:-:*:*:*:*:*:*:*
intel core_i3_9100f_firmware cpe:2.3:o:intel:core_i3_9100f_firmware:-:*:*:*:*:*:*:*
intel core_i3_9100t_firmware cpe:2.3:o:intel:core_i3_9100t_firmware:-:*:*:*:*:*:*:*
intel core_i3_9300_firmware cpe:2.3:o:intel:core_i3_9300_firmware:-:*:*:*:*:*:*:*
intel core_i3_9300t_firmware cpe:2.3:o:intel:core_i3_9300t_firmware:-:*:*:*:*:*:*:*
intel core_i3_9320_firmware cpe:2.3:o:intel:core_i3_9320_firmware:-:*:*:*:*:*:*:*
intel core_i3_9350k_firmware cpe:2.3:o:intel:core_i3_9350k_firmware:-:*:*:*:*:*:*:*
intel core_i3_9350kf_firmware cpe:2.3:o:intel:core_i3_9350kf_firmware:-:*:*:*:*:*:*:*
intel core_i5_firmware cpe:2.3:o:intel:core_i5_firmware:-:*:*:*:*:*:*:*
intel core_i5\+8400_firmware cpe:2.3:o:intel:core_i5\+8400_firmware:-:*:*:*:*:*:*:*
intel core_i5\+8500_firmware cpe:2.3:o:intel:core_i5\+8500_firmware:-:*:*:*:*:*:*:*
intel core_i5-10110y_firmware cpe:2.3:o:intel:core_i5-10110y_firmware:-:*:*:*:*:*:*:*
intel core_i5-10200h_firmware cpe:2.3:o:intel:core_i5-10200h_firmware:-:*:*:*:*:*:*:*
intel core_i5-10210u_firmware cpe:2.3:o:intel:core_i5-10210u_firmware:-:*:*:*:*:*:*:*
intel core_i5-10210y_firmware cpe:2.3:o:intel:core_i5-10210y_firmware:-:*:*:*:*:*:*:*
intel core_i5-10300h_firmware cpe:2.3:o:intel:core_i5-10300h_firmware:-:*:*:*:*:*:*:*
intel core_i5-1030g4_firmware cpe:2.3:o:intel:core_i5-1030g4_firmware:-:*:*:*:*:*:*:*
intel core_i5-1030g7_firmware cpe:2.3:o:intel:core_i5-1030g7_firmware:-:*:*:*:*:*:*:*
intel core_i5-1030ng7_firmware cpe:2.3:o:intel:core_i5-1030ng7_firmware:-:*:*:*:*:*:*:*
intel core_i5-10310u_firmware cpe:2.3:o:intel:core_i5-10310u_firmware:-:*:*:*:*:*:*:*
intel core_i5-10310y_firmware cpe:2.3:o:intel:core_i5-10310y_firmware:-:*:*:*:*:*:*:*
intel core_i5-1035g1_firmware cpe:2.3:o:intel:core_i5-1035g1_firmware:-:*:*:*:*:*:*:*
intel core_i5-1035g4_firmware cpe:2.3:o:intel:core_i5-1035g4_firmware:-:*:*:*:*:*:*:*
intel core_i5-1035g7_firmware cpe:2.3:o:intel:core_i5-1035g7_firmware:-:*:*:*:*:*:*:*
intel core_i5-1038ng7_firmware cpe:2.3:o:intel:core_i5-1038ng7_firmware:-:*:*:*:*:*:*:*
intel core_i5-10400_firmware cpe:2.3:o:intel:core_i5-10400_firmware:-:*:*:*:*:*:*:*
intel core_i5-10400f_firmware cpe:2.3:o:intel:core_i5-10400f_firmware:-:*:*:*:*:*:*:*
intel core_i5-10400h_firmware cpe:2.3:o:intel:core_i5-10400h_firmware:-:*:*:*:*:*:*:*
intel core_i5-10400t_firmware cpe:2.3:o:intel:core_i5-10400t_firmware:-:*:*:*:*:*:*:*
intel core_i5-10500_firmware cpe:2.3:o:intel:core_i5-10500_firmware:-:*:*:*:*:*:*:*
intel core_i5-10500e_firmware cpe:2.3:o:intel:core_i5-10500e_firmware:-:*:*:*:*:*:*:*
intel core_i5-10500h_firmware cpe:2.3:o:intel:core_i5-10500h_firmware:-:*:*:*:*:*:*:*
intel core_i5-10500t_firmware cpe:2.3:o:intel:core_i5-10500t_firmware:-:*:*:*:*:*:*:*
intel core_i5-10500te_firmware cpe:2.3:o:intel:core_i5-10500te_firmware:-:*:*:*:*:*:*:*
intel core_i5-10505_firmware cpe:2.3:o:intel:core_i5-10505_firmware:-:*:*:*:*:*:*:*
intel core_i5-10600_firmware cpe:2.3:o:intel:core_i5-10600_firmware:-:*:*:*:*:*:*:*
intel core_i5-10600k_firmware cpe:2.3:o:intel:core_i5-10600k_firmware:-:*:*:*:*:*:*:*
intel core_i5-10600kf_firmware cpe:2.3:o:intel:core_i5-10600kf_firmware:-:*:*:*:*:*:*:*
intel core_i5-10600t_firmware cpe:2.3:o:intel:core_i5-10600t_firmware:-:*:*:*:*:*:*:*
intel core_i5-10610u_firmware cpe:2.3:o:intel:core_i5-10610u_firmware:-:*:*:*:*:*:*:*
intel core_i5_10110y_firmware cpe:2.3:o:intel:core_i5_10110y_firmware:-:*:*:*:*:*:*:*
intel core_i5_10210y_firmware cpe:2.3:o:intel:core_i5_10210y_firmware:-:*:*:*:*:*:*:*
intel core_i5_10310y_firmware cpe:2.3:o:intel:core_i5_10310y_firmware:-:*:*:*:*:*:*:*
intel core_i5_8400_firmware cpe:2.3:o:intel:core_i5_8400_firmware:-:*:*:*:*:*:*:*
intel core_i5_8400t_firmware cpe:2.3:o:intel:core_i5_8400t_firmware:-:*:*:*:*:*:*:*
intel core_i5_8500_firmware cpe:2.3:o:intel:core_i5_8500_firmware:-:*:*:*:*:*:*:*

References for CVE-2021-33107

cvelogic Threat Intelligence