CVE-2021-33146

Improper input validation in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow an unauthenticated user to potentially enable information disclosure via network access.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:intel:ethernet_controller_i225-it_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:intel:ethernet_controller_i225-it:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:intel:ethernet_controller_i225-lm_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:intel:ethernet_controller_i225-lm:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:intel:ethernet_controller_i225-v_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:intel:ethernet_controller_i225-v:-:*:*:*:*:*:*:*

Configuration 4 (hide)

cpe:2.3:a:intel:ethernet_adapter_complete_driver:*:*:*:*:*:*:*:*

History

09 Jan 2026, 19:49

Type Values Removed Values Added
CPE cpe:2.3:h:intel:ethernet_controller_i225-lm:-:*:*:*:*:*:*:*
cpe:2.3:o:intel:ethernet_controller_i225-it_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:intel:ethernet_controller_i225-v:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:ethernet_controller_i225-it:-:*:*:*:*:*:*:*
cpe:2.3:a:intel:ethernet_adapter_complete_driver:*:*:*:*:*:*:*:*
cpe:2.3:o:intel:ethernet_controller_i225-v_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:intel:ethernet_controller_i225-lm_firmware:*:*:*:*:*:*:*:*
References () https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00756.html - () https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00756.html - Vendor Advisory
First Time Intel ethernet Controller I225-it
Intel ethernet Controller I225-it Firmware
Intel
Intel ethernet Controller I225-lm
Intel ethernet Adapter Complete Driver
Intel ethernet Controller I225-v
Intel ethernet Controller I225-v Firmware
Intel ethernet Controller I225-lm Firmware

21 Nov 2024, 06:08

Type Values Removed Values Added
References () https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00756.html - () https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00756.html -

03 Jul 2024, 01:36

Type Values Removed Values Added
Summary
  • (es) La validación de entrada incorrecta en algunos adaptadores Intel(R) Ethernet y en el firmware de capacidad de administración del controlador Intel(R) Ethernet I225 puede permitir que un usuario no autenticado habilite potencialmente la divulgación de información a través del acceso a la red.
CWE CWE-200

16 May 2024, 21:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
CWE CWE-20
Summary (en) Rejected reason: This is unused. (en) Improper input validation in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow an unauthenticated user to potentially enable information disclosure via network access.
References
  • () https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00756.html -

29 Feb 2024, 01:31

Type Values Removed Values Added

23 Feb 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-23 21:15

Updated : 2026-01-09 19:49


NVD link : CVE-2021-33146

Mitre link : CVE-2021-33146

CVE.ORG link : CVE-2021-33146


JSON object : View

Products Affected

intel

  • ethernet_controller_i225-it
  • ethernet_adapter_complete_driver
  • ethernet_controller_i225-lm_firmware
  • ethernet_controller_i225-v
  • ethernet_controller_i225-v_firmware
  • ethernet_controller_i225-lm
  • ethernet_controller_i225-it_firmware
CWE
CWE-20

Improper Input Validation

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor