← Vulnerability feed

Vulnerability record · CVE-2022-33196 · published 16 February 2023

CVE-2022-33196: Intel xeon gold 5315y firmware incorrect default permissions vulnerability

Intel · Xeon Gold 5315y Firmware

Incorrect default permissions in some memory controller configurations for some Intel(R) Xeon(R) Processors when using Intel(R) Software Guard Extensions which may allow a privileged user to potentially enable escalation of privilege via local access.

6.7 CVSS 3.1 Medium EPSS 0.21% · top 89.6% CWE-276 · Incorrect default permissions
6.7CVSS 3.1 base score
0.21%EPSS exploitation probability, 30 days
NoNot in CISA KEV
136Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Incorrect default permissions in some memory controller configurations for some Intel(R) Xeon(R) Processors when using Intel(R) Software Guard Extensions which may allow a privileged user to potentially enable escalation of privilege via local access.

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected products

136 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-33196 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.2CVE-2019-11137Intel xeon platinum 8253 firmware improper input validation vulnerabilityInsufficient input validation in system firmware for Intel(R) Xeon(R) Scalable Processors, Intel(R) Xeon(R) Processors D Family, Intel(R) Xeon(R) Pro…EPSS 0.38%7.8CVE-2023-23583Intel core i3-10100y firmware incorrect default permissions vulnerabilitySequence of processor instructions leads to unexpected behavior for some Intel(R) Processors may allow an authenticated user to potentially enable es…EPSS 1.7%7.8CVE-2021-33123Intel xeon bronze 3206r firmware vulnerabilityImproper access control in the BIOS authenticated code module for some Intel(R) Processors may allow a privileged user to potentially enable aescalat…EPSS 0.26%7.8CVE-2021-0154Intel xeon e-2314 firmware improper input validation vulnerabilityImproper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privileg…EPSS 0.27%6.7CVE-2022-41804Debian linux vulnerabilityUnauthorized error injection in Intel(R) SGX or Intel(R) TDX for some Intel(R) Xeon(R) Processors may allow a privileged user to potentially enable e…EPSS 0.27%6.7CVE-2022-37343Intel atom c3338r firmware improper access control vulnerabilityImproper access control in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege v…EPSS 0.17%6.7CVE-2022-26343Intel xeon bronze 3104 firmware vulnerabilityImproper access control in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege v…EPSS 0.25%6.7CVE-2021-33124Intel xeon bronze 3206r firmware out-of-bounds write vulnerabilityOut-of-bounds write in the BIOS authenticated code module for some Intel(R) Processors may allow a privileged user to potentially enable aescalation …EPSS 0.26%

Source: NIST National Vulnerability Database (record CVE-2022-33196), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.