Got a laptop or appliance running one of Intel’s low-power CPUs? A BIOS update might be in order. A vulnerability affecting multiple Intel processor families was disclosed today by researchers at Positive Technologies.

The high-severity vulnerability (CVE-2021-0146) allows an attacker to extract encryption keys and obtain enhanced privileges on devices running Intel’s Apollo Lake- and Gemini Lake-based Pentium, Celeron, and Atom processors. These chips are widely used in mobile devices, embedded systems, IoT, home appliances, medical equipment — and, thanks to their low-power consumption, are a popular choice for small-form-factor whitebox CPE like routers and firewalls.

Affected chips also include Intel’s Atom E3900, which has seen wide deployment in the automative sector in at least 30 vehicles.

Discovered by Positive Technologies researchers Mark Ermolov and Dmitry Sklyarov, along with independent threat researcher Maxim Goryachy, the vulnerability boils down to excessive privileges provided by the chip’s integrated debugging functionality.

An attacker with physical access to the hardware could exploit this weakness to extract encrypted information from an effected device.

“The bug can also be exploited in targeted attacks across the supply chain,” Ermolov warned. “For example, an employee of an Intel processor-based device supplier could, in theory, extract the Intel CSME [Converged Security and Management Engine] firmware key and deploy spyware that security software would not detect.”

The vulnerability is “dangerous” because it can be used to extract the root encryption key used by Intel’s Platform Trust Technology and Enhanced Privacy ID technologies, which are commonly used to safeguard digital content from illegal duplication, Ermolov added.

In response to this threat, Intel released a firmware mitigation for affected systems.  Positive Technologies advises users update the BIOS on affected hardware at the earliest opportunity, and it recommends using a security information and event management (SEIM) platform to detect to monitor for breaches.