← Vulnerability feed

Vulnerability record · CVE-2021-0111 · published 9 February 2022

CVE-2021-0111: Intel atom c3308 null pointer dereference vulnerability

Intel · Atom C3308

NULL pointer dereference in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access.

6.7 CVSS 3.1 Medium EPSS 0.30% · top 79.7% CWE-476 · NULL pointer dereference
6.7CVSS 3.1 base score, v2 4.6
0.30%EPSS exploitation probability, 30 days
NoNot in CISA KEV
150Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

NULL pointer dereference in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access.

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected products

150 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-0111 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2021-0091Intel atom c3308 vulnerabilityImproper access control in the firmware for some Intel(R) Processors may allow an unauthenticated user to potentially enable an escalation of privile…EPSS 0.33%7.8CVE-2021-0099Intel atom c3308 vulnerabilityInsufficient control flow management in the firmware for some Intel(R) Processors may allow an authenticated user to potentially enable an escalation…EPSS 0.30%6.8CVE-2021-33150Intel atom c2308 vulnerabilityHardware allows activation of test or debug logic at runtime for some Intel(R) Trace Hub instances which may allow an unauthenticated user to potenti…EPSS 0.35%6.7CVE-2021-0115Intel atom c3308 classic buffer overflow vulnerabilityBuffer overflow in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local acce…EPSS 0.33%6.7CVE-2021-0103Intel atom c3308 vulnerabilityInsufficient control flow management in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of …EPSS 0.30%6.7CVE-2021-0107Intel atom c3308 unchecked return value vulnerabilityUnchecked return value in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via loc…EPSS 0.30%6.7CVE-2021-0114Intel atom c3000 insecure default initialization vulnerabilityUnchecked return value in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via …EPSS 0.27%6.7CVE-2021-0144Intel atom c3000 insecure default initialization vulnerabilityInsecure default variable initialization for the Intel BSSA DFT feature may allow a privileged user to potentially enable an escalation of privilege …EPSS 0.33%

Source: NIST National Vulnerability Database (record CVE-2021-0111), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.