CVE-2021-23168: Medium severity intel wireless-ac 9560 vulnerability
Out of bounds read for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow an unauthenticated user to potentially enable denial of service via adjacent access.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-23168?
CVE-2021-23168 is a vulnerability that allows an unauthenticated user to potentially enable denial of service via adjacent access on some Intel PROSet/Wireless WiFi and Killer WiFi products.
How severe is CVE-2021-23168?
CVE-2021-23168 has a severity level of 6.5, which is considered medium.
Which software products are affected by CVE-2021-23168?
The following Intel wireless products are affected: Intel Wireless-ac 9560 Firmware, Intel Dual Band Wireless-ac 3165 Firmware, Intel Dual Band Wireless-ac 3168 Firmware, Intel Wireless-ac 9462 Firmware, Intel Wireless-ac 9461 Firmware, Intel Killer Ac 1550 Firmware, Intel Killer Wi-fi 6 Ax1650 Firmware, Intel Dual Band Wireless-ac 8260 Firmware, Intel Dual Band Wireless-ac 8265 Firmware, Intel Killer Wi-fi 6e Ax1690 Firmware, Intel Killer Wi-fi 6e Ax1675 Firmware, Intel Wireless-ac 9260 Firmware, Intel Proset Wi-fi 6e Ax210 Firmware, Intel Wi-fi 6e Ax211 Firmware, Intel Wi-fi 6 Ax200 Firmware, Intel Wi-fi 6 Ax201 Firmware, Intel Wi-fi 6e Ax411 Firmware, and Intel Wireless 7265 (rev D) Firmware.
How can I fix CVE-2021-23168?
To fix CVE-2021-23168, it is recommended to update the firmware of the affected Intel wireless products to a version above 22.120 or 3.1122.1105, depending on the specific product.
Where can I find more information about CVE-2021-23168?
For more information about CVE-2021-23168, you can visit the following references: [Debian LTS Announcement](https://lists.debian.org/debian-lts-announce/2023/04/msg00002.html) and [Intel Security Advisory](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00621.html).