/
cyberknowledge
/
CVE
ОбзорДокументацияВойти
/
cyberknowledge
/
CVE
Код
Запросы
0
Задачи
Вики
Пакеты
0
Релизы
0
CI/CD
Аналитика
ДокументацияПоддержка
Политика конфиденциальностиПользовательское соглашениеПолитика использования «cookies»Согласие субъекта персональных данных
2026 ©
samples/intel_advisories.csv
106 строк857 KB

Zeros312

Rename sample/ to samples/; remove README from samples
30 июн 2026, 21:21
30 июн 2026, 21:2183c96cb
100 строк
CVE-2024-25571
INTEL-SA-01120
Intel® SPS Firmware Advisory
A potential security vulnerability in some Intel® Server Platform Services (Intel® SPS) firmware may allow denial of service. Intel is releasing firmware updates to mitigate this potential vulnerability.
LOW
2025-02-11 03:00:00+03:00
2025-02-11 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01120.html
3f53b24ef18b4ca0e0ef3ab465f08c9de01914b5897e420da527b8440b9d7245
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® Server Platform Services (Intel® SPS) firmware may allow denial of service. Intel is releasing firmware updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of Intel® SPS update to the latest version provided by the system manufacturer that addresses these issues.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Low', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Denial of Service', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® SPS Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01120', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2025-02-11T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2025-02-11T00:00:00+00:00', 'initial_release_date': '2025-02-11T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01120.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Copyright © Intel Corporation All rights reserved.'}, 'acknowledgments': [{'names': ['This issue was found internally by Intel employees.\xa0 Intel would like to thank Tomasz Bagniuk, Bartosz Górski, and Piotr Dorożyński. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-25571', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'title': 'Improper input validation in some Intel® SPS firmware before SPS_E5_06.01.04.059.0 may allow a privileged user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 2.3, 'attackVector': 'LOCAL', 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'HIGH', 'confidentialityImpact': 'NONE'}, 'cvss_v4': {'version': '4.0', 'baseScore': 4.6, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'HIGH', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'NONE', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'LOW', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'NONE'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-21807
INTEL-SA-00918
Intel® Ethernet Controllers and Adapters Advisory
Potential security vulnerabilities in some Intel® Ethernet Controllers and Adapters may allow escalation of privilege or denial of service. Intel is releasing firmware and software updates to mitigate these potential vulnerabilities.
HIGH
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00918.html
85c2bf7afb1ed3a34edb4603d452cb6e4ce074fd75bc395f6ab8479f5c37d620
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® Ethernet Controllers and Adapters may allow escalation of privilege or denial of service. Intel is releasing firmware and software updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating the software for impacted Intel® Ethernet Controllers and Adapters to the versions provided below or later.\r\n\xa0\r\nUpdate to Intel® Ethernet Complete Driver Pack versions 28.3 or later.\r\nIntel® Ethernet Controllers E800 Series with NVM image versions 4.4 or higher included with Intel® Ethernet Adapter Complete Driver Pack versions 28.3 or higher.\xa0\r\nIntel recommends updating the firmware for impacted Intel® Ethernet Controllers and Adapters to the versions provided below or later.\r\nUpdate firmware to NIC1.3 PV, NVM image version 3.36 or higher included Intel(R) Ethernet Complete Driver Pack versions 28.3 or later.\r\nUpdates are available for download at this location:\xa0\xa0Intel® Ethernet Adapter Complete Driver Pack', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware,software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Ethernet Controllers and Adapters Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-00918', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00918.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['The following issues were found internally by Intel employees: CVE-2024-23981, CVE-2024-21810, CVE-2024-21807, CVE-2024-23497, CVE-and 2024-24986. Intel would like to thank Daniel Medina Velazquez and Thierry Fernandes Faria.\xa0\r\nThe following issues were found internally by Intel employees: CVE-2024-21806, CVE-2024-23499 and CVE-2024-24983.\xa0\r\nIntel would like to thank mohammed for reporting CVE-2024-21769. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-21810', 'title': 'Improper input validation in the Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23497', 'title': 'Out-of-bounds write in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-24983', 'title': 'Protection mechanism failure in firmware for some Intel® Ethernet Network Controllers and Adapters E810 Series before version 4.4 may allow an unauthenticated user to potentially enable denial of service via network access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21807', 'title': 'Improper initialization in the Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23981', 'title': 'Wrap-around error in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23499', 'title': 'Protection mechanism failure in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters E810 Series before version 28.3 may allow an unauthenticated user to potentially enable denial of service via network access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21769', 'title': ' Uncontrolled search path in some Intel® Ethernet Connection I219-LM install software may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-24986', 'title': 'Improper access control in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21806', 'title': 'Improper conditions check in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters E810 Series before version 28.3 may allow an authenticated user to potentially enable denial of service via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-23981
INTEL-SA-00918
Intel® Ethernet Controllers and Adapters Advisory
Potential security vulnerabilities in some Intel® Ethernet Controllers and Adapters may allow escalation of privilege or denial of service. Intel is releasing firmware and software updates to mitigate these potential vulnerabilities.
HIGH
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00918.html
25eda300d74f221d61540265eadd81ca43641540b5ecd985c3ef5d7f3807faa0
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® Ethernet Controllers and Adapters may allow escalation of privilege or denial of service. Intel is releasing firmware and software updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating the software for impacted Intel® Ethernet Controllers and Adapters to the versions provided below or later.\r\n\xa0\r\nUpdate to Intel® Ethernet Complete Driver Pack versions 28.3 or later.\r\nIntel® Ethernet Controllers E800 Series with NVM image versions 4.4 or higher included with Intel® Ethernet Adapter Complete Driver Pack versions 28.3 or higher.\xa0\r\nIntel recommends updating the firmware for impacted Intel® Ethernet Controllers and Adapters to the versions provided below or later.\r\nUpdate firmware to NIC1.3 PV, NVM image version 3.36 or higher included Intel(R) Ethernet Complete Driver Pack versions 28.3 or later.\r\nUpdates are available for download at this location:\xa0\xa0Intel® Ethernet Adapter Complete Driver Pack', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware,software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Ethernet Controllers and Adapters Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-00918', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00918.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['The following issues were found internally by Intel employees: CVE-2024-23981, CVE-2024-21810, CVE-2024-21807, CVE-2024-23497, CVE-and 2024-24986. Intel would like to thank Daniel Medina Velazquez and Thierry Fernandes Faria.\xa0\r\nThe following issues were found internally by Intel employees: CVE-2024-21806, CVE-2024-23499 and CVE-2024-24983.\xa0\r\nIntel would like to thank mohammed for reporting CVE-2024-21769. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-21810', 'title': 'Improper input validation in the Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23497', 'title': 'Out-of-bounds write in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-24983', 'title': 'Protection mechanism failure in firmware for some Intel® Ethernet Network Controllers and Adapters E810 Series before version 4.4 may allow an unauthenticated user to potentially enable denial of service via network access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21807', 'title': 'Improper initialization in the Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23981', 'title': 'Wrap-around error in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23499', 'title': 'Protection mechanism failure in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters E810 Series before version 28.3 may allow an unauthenticated user to potentially enable denial of service via network access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21769', 'title': ' Uncontrolled search path in some Intel® Ethernet Connection I219-LM install software may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-24986', 'title': 'Improper access control in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21806', 'title': 'Improper conditions check in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters E810 Series before version 28.3 may allow an authenticated user to potentially enable denial of service via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-28036
INTEL-SA-01252
Intel® Arc™ GPU Advisory
A potential security vulnerability in some Intel® Arc™ GPU may allow denial of service. Intel is releasing software updates to mitigate this potential vulnerability.
MEDIUM
2025-05-13 03:00:00+03:00
2025-05-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01252.html
459d78d18ea7da45411c1ab77f0ff78a729d4ba133e86776851a16ef5d98b5bd
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® Arc™ GPU may allow denial of service. Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating Intel® Arc™ A-series graphics software to version 31.0.101.3277 or later.Updates are available for download at this location:https://www.intel.com/content/www/us/en/download/785597\r\n\xa0\r\nIntel recommends updating Intel® Arc™ Pro A-series graphics software to version 30.0.101.1729 or later.Updates are available for download at this location:https://www.intel.com/content/www/us/en/download/741626', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Hardware,software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Denial of Service', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Arc™ GPU Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01252', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2025-05-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2025-05-13T00:00:00+00:00', 'initial_release_date': '2025-05-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01252.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Copyright © Intel Corporation All rights reserved.'}, 'acknowledgments': [{'names': ['This issue was found internally by Intel employees. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-28036', 'cwe': {'id': 'CWE-754', 'name': 'Improper conditions check'}, 'title': 'Improper conditions check for some Intel® Arc™ GPU may allow an authenticated user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 5.6, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.7, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'attackRequirements': 'NONE', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'NONE', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'HIGH', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'NONE'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2025-20079
INTEL-SA-01263
Intel® Advisor Software Advisory
Potential security vulnerability for some Intel® Advisor software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.
MEDIUM
2025-05-13 03:00:00+03:00
2025-05-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01263.html
c1976a0f5d1b5ca5b2b306b81e0c3cef9486f167b4e94790c4d20b9b7e8d77b2
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerability for some Intel® Advisor software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating Intel® Advisor standalone component software software to version 2024.2 or later.\xa0\xa0\r\nUpdates are available for download at this location:\r\nhttps://www.intel.com/content/www/us/en/developer/tools/oneapi/advisor.html\r\n\xa0\r\nIntel recommends updating Intel® oneAPI Base Toolkit to 2024.2 or later.\r\nUpdates are available for download at this location:\r\nhttps://www.intel.com/content/www/us/en/developer/tools/oneapi/base-toolkit.html', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Advisor Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01263', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2025-05-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2025-05-13T00:00:00+00:00', 'initial_release_date': '2025-05-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01263.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Copyright © Intel Corporation All rights reserved.'}, 'acknowledgments': [{'names': ['Intel would like to thank ycdxsb for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2025-20079', 'cwe': {'id': 'CWE-427', 'name': 'Uncontrolled search path'}, 'title': 'Uncontrolled search path for some Intel® Advisor software may allow an authenticated user to potentially enable escalation of privilege via local access.\r\n', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.7, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'HIGH', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'userInteraction': 'ACTIVE', 'attackComplexity': 'HIGH', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'HIGH', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2025-21093
INTEL-SA-01321
Intel® Driver & Support Assistant Tool Advisory
A potential security vulnerability for some Intel® Driver & Support Assistant Tool software may allow escalation of privilege, Intel is releasing software updates to mitigate this potential vulnerability.
MEDIUM
2025-08-12 03:00:00+03:00
2025-08-12 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01321.html
305357e5e628e9749b90f5f40687a3dd036313d47f93280e826f00dd20f9d79a
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability for some Intel® Driver & Support Assistant Tool software may allow escalation of privilege, Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating the Intel® Driver & Support Assistant Tool software to version 24.6.49.8 or later.\r\nUpdates are available for download at this location:https://www.intel.com/content/www/us/en/support/detect.html', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Driver & Support Assistant Tool Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01321', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2025-08-12T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2025-08-12T00:00:00+00:00', 'initial_release_date': '2025-08-12T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01321.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Copyright © Intel Corporation All rights reserved.'}, 'acknowledgments': [{'names': ['Intel would like to thank FalconCorruption for reporting these issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2025-21093', 'cwe': {'id': 'CWE-427', 'name': 'Uncontrolled search path'}, 'title': 'Uncontrolled search path element for some Intel® Driver & Support Assistant Tool software before version 24.6.49.8 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.7, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'HIGH', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'userInteraction': 'PASSIVE', 'attackComplexity': 'HIGH', 'attackRequirements': 'NONE', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'HIGH', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-23499
INTEL-SA-00918
Intel® Ethernet Controllers and Adapters Advisory
Potential security vulnerabilities in some Intel® Ethernet Controllers and Adapters may allow escalation of privilege or denial of service. Intel is releasing firmware and software updates to mitigate these potential vulnerabilities.
HIGH
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00918.html
6b4a9ce24fdfd28a9652b79a459e83dcf9e7137a5da7fde1fe2cf141bbadcaca
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® Ethernet Controllers and Adapters may allow escalation of privilege or denial of service. Intel is releasing firmware and software updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating the software for impacted Intel® Ethernet Controllers and Adapters to the versions provided below or later.\r\n\xa0\r\nUpdate to Intel® Ethernet Complete Driver Pack versions 28.3 or later.\r\nIntel® Ethernet Controllers E800 Series with NVM image versions 4.4 or higher included with Intel® Ethernet Adapter Complete Driver Pack versions 28.3 or higher.\xa0\r\nIntel recommends updating the firmware for impacted Intel® Ethernet Controllers and Adapters to the versions provided below or later.\r\nUpdate firmware to NIC1.3 PV, NVM image version 3.36 or higher included Intel(R) Ethernet Complete Driver Pack versions 28.3 or later.\r\nUpdates are available for download at this location:\xa0\xa0Intel® Ethernet Adapter Complete Driver Pack', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware,software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Ethernet Controllers and Adapters Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-00918', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00918.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['The following issues were found internally by Intel employees: CVE-2024-23981, CVE-2024-21810, CVE-2024-21807, CVE-2024-23497, CVE-and 2024-24986. Intel would like to thank Daniel Medina Velazquez and Thierry Fernandes Faria.\xa0\r\nThe following issues were found internally by Intel employees: CVE-2024-21806, CVE-2024-23499 and CVE-2024-24983.\xa0\r\nIntel would like to thank mohammed for reporting CVE-2024-21769. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-21810', 'title': 'Improper input validation in the Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23497', 'title': 'Out-of-bounds write in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-24983', 'title': 'Protection mechanism failure in firmware for some Intel® Ethernet Network Controllers and Adapters E810 Series before version 4.4 may allow an unauthenticated user to potentially enable denial of service via network access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21807', 'title': 'Improper initialization in the Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23981', 'title': 'Wrap-around error in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23499', 'title': 'Protection mechanism failure in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters E810 Series before version 28.3 may allow an unauthenticated user to potentially enable denial of service via network access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21769', 'title': ' Uncontrolled search path in some Intel® Ethernet Connection I219-LM install software may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-24986', 'title': 'Improper access control in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21806', 'title': 'Improper conditions check in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters E810 Series before version 28.3 may allow an authenticated user to potentially enable denial of service via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-21769
INTEL-SA-00918
Intel® Ethernet Controllers and Adapters Advisory
Potential security vulnerabilities in some Intel® Ethernet Controllers and Adapters may allow escalation of privilege or denial of service. Intel is releasing firmware and software updates to mitigate these potential vulnerabilities.
HIGH
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00918.html
d0d75d152b9dc1fb2e88add37fe6359b37709185c3c80423c01685ce9aadf3bf
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® Ethernet Controllers and Adapters may allow escalation of privilege or denial of service. Intel is releasing firmware and software updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating the software for impacted Intel® Ethernet Controllers and Adapters to the versions provided below or later.\r\n\xa0\r\nUpdate to Intel® Ethernet Complete Driver Pack versions 28.3 or later.\r\nIntel® Ethernet Controllers E800 Series with NVM image versions 4.4 or higher included with Intel® Ethernet Adapter Complete Driver Pack versions 28.3 or higher.\xa0\r\nIntel recommends updating the firmware for impacted Intel® Ethernet Controllers and Adapters to the versions provided below or later.\r\nUpdate firmware to NIC1.3 PV, NVM image version 3.36 or higher included Intel(R) Ethernet Complete Driver Pack versions 28.3 or later.\r\nUpdates are available for download at this location:\xa0\xa0Intel® Ethernet Adapter Complete Driver Pack', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware,software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Ethernet Controllers and Adapters Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-00918', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00918.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['The following issues were found internally by Intel employees: CVE-2024-23981, CVE-2024-21810, CVE-2024-21807, CVE-2024-23497, CVE-and 2024-24986. Intel would like to thank Daniel Medina Velazquez and Thierry Fernandes Faria.\xa0\r\nThe following issues were found internally by Intel employees: CVE-2024-21806, CVE-2024-23499 and CVE-2024-24983.\xa0\r\nIntel would like to thank mohammed for reporting CVE-2024-21769. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-21810', 'title': 'Improper input validation in the Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23497', 'title': 'Out-of-bounds write in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-24983', 'title': 'Protection mechanism failure in firmware for some Intel® Ethernet Network Controllers and Adapters E810 Series before version 4.4 may allow an unauthenticated user to potentially enable denial of service via network access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21807', 'title': 'Improper initialization in the Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23981', 'title': 'Wrap-around error in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23499', 'title': 'Protection mechanism failure in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters E810 Series before version 28.3 may allow an unauthenticated user to potentially enable denial of service via network access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21769', 'title': ' Uncontrolled search path in some Intel® Ethernet Connection I219-LM install software may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-24986', 'title': 'Improper access control in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21806', 'title': 'Improper conditions check in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters E810 Series before version 28.3 may allow an authenticated user to potentially enable denial of service via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-24986
INTEL-SA-00918
Intel® Ethernet Controllers and Adapters Advisory
Potential security vulnerabilities in some Intel® Ethernet Controllers and Adapters may allow escalation of privilege or denial of service. Intel is releasing firmware and software updates to mitigate these potential vulnerabilities.
HIGH
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00918.html
488b0bc081134ed473df47a7a82822f40940eb3eb2426c3ee7e70a1f30ea9db3
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® Ethernet Controllers and Adapters may allow escalation of privilege or denial of service. Intel is releasing firmware and software updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating the software for impacted Intel® Ethernet Controllers and Adapters to the versions provided below or later.\r\n\xa0\r\nUpdate to Intel® Ethernet Complete Driver Pack versions 28.3 or later.\r\nIntel® Ethernet Controllers E800 Series with NVM image versions 4.4 or higher included with Intel® Ethernet Adapter Complete Driver Pack versions 28.3 or higher.\xa0\r\nIntel recommends updating the firmware for impacted Intel® Ethernet Controllers and Adapters to the versions provided below or later.\r\nUpdate firmware to NIC1.3 PV, NVM image version 3.36 or higher included Intel(R) Ethernet Complete Driver Pack versions 28.3 or later.\r\nUpdates are available for download at this location:\xa0\xa0Intel® Ethernet Adapter Complete Driver Pack', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware,software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Ethernet Controllers and Adapters Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-00918', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00918.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['The following issues were found internally by Intel employees: CVE-2024-23981, CVE-2024-21810, CVE-2024-21807, CVE-2024-23497, CVE-and 2024-24986. Intel would like to thank Daniel Medina Velazquez and Thierry Fernandes Faria.\xa0\r\nThe following issues were found internally by Intel employees: CVE-2024-21806, CVE-2024-23499 and CVE-2024-24983.\xa0\r\nIntel would like to thank mohammed for reporting CVE-2024-21769. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-21810', 'title': 'Improper input validation in the Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23497', 'title': 'Out-of-bounds write in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-24983', 'title': 'Protection mechanism failure in firmware for some Intel® Ethernet Network Controllers and Adapters E810 Series before version 4.4 may allow an unauthenticated user to potentially enable denial of service via network access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21807', 'title': 'Improper initialization in the Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23981', 'title': 'Wrap-around error in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23499', 'title': 'Protection mechanism failure in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters E810 Series before version 28.3 may allow an unauthenticated user to potentially enable denial of service via network access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21769', 'title': ' Uncontrolled search path in some Intel® Ethernet Connection I219-LM install software may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-24986', 'title': 'Improper access control in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21806', 'title': 'Improper conditions check in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters E810 Series before version 28.3 may allow an authenticated user to potentially enable denial of service via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-21806
INTEL-SA-00918
Intel® Ethernet Controllers and Adapters Advisory
Potential security vulnerabilities in some Intel® Ethernet Controllers and Adapters may allow escalation of privilege or denial of service. Intel is releasing firmware and software updates to mitigate these potential vulnerabilities.
HIGH
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00918.html
6fa993532c299ed80d7606758382456d337c2fea9f8221acb31ecdc03d3349d7
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® Ethernet Controllers and Adapters may allow escalation of privilege or denial of service. Intel is releasing firmware and software updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating the software for impacted Intel® Ethernet Controllers and Adapters to the versions provided below or later.\r\n\xa0\r\nUpdate to Intel® Ethernet Complete Driver Pack versions 28.3 or later.\r\nIntel® Ethernet Controllers E800 Series with NVM image versions 4.4 or higher included with Intel® Ethernet Adapter Complete Driver Pack versions 28.3 or higher.\xa0\r\nIntel recommends updating the firmware for impacted Intel® Ethernet Controllers and Adapters to the versions provided below or later.\r\nUpdate firmware to NIC1.3 PV, NVM image version 3.36 or higher included Intel(R) Ethernet Complete Driver Pack versions 28.3 or later.\r\nUpdates are available for download at this location:\xa0\xa0Intel® Ethernet Adapter Complete Driver Pack', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware,software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Ethernet Controllers and Adapters Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-00918', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00918.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['The following issues were found internally by Intel employees: CVE-2024-23981, CVE-2024-21810, CVE-2024-21807, CVE-2024-23497, CVE-and 2024-24986. Intel would like to thank Daniel Medina Velazquez and Thierry Fernandes Faria.\xa0\r\nThe following issues were found internally by Intel employees: CVE-2024-21806, CVE-2024-23499 and CVE-2024-24983.\xa0\r\nIntel would like to thank mohammed for reporting CVE-2024-21769. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-21810', 'title': 'Improper input validation in the Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23497', 'title': 'Out-of-bounds write in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-24983', 'title': 'Protection mechanism failure in firmware for some Intel® Ethernet Network Controllers and Adapters E810 Series before version 4.4 may allow an unauthenticated user to potentially enable denial of service via network access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21807', 'title': 'Improper initialization in the Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23981', 'title': 'Wrap-around error in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23499', 'title': 'Protection mechanism failure in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters E810 Series before version 28.3 may allow an unauthenticated user to potentially enable denial of service via network access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21769', 'title': ' Uncontrolled search path in some Intel® Ethernet Connection I219-LM install software may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-24986', 'title': 'Improper access control in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21806', 'title': 'Improper conditions check in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters E810 Series before version 28.3 may allow an authenticated user to potentially enable denial of service via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2021-37577
INTEL-SA-00606
Intel® Wireless Bluetooth® and Killer™ Bluetooth® Advisory
A potential security vulnerability in some Intel® Wireless Bluetooth® and Killer™ Bluetooth® products may allow escalation of privilege. Intel is releasing firmware updates to mitigate this potential vulnerability.
MEDIUM
2025-02-11 03:00:00+03:00
2025-02-11 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00606.html
0d0dc10e5ba86274b2ff1a8e981409a4da6fc7b3d36d9fdf415ab209cdd3894f
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® Wireless Bluetooth® and Killer™ Bluetooth® products may allow escalation of privilege. Intel is releasing firmware updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating the affected Intel® Wireless Bluetooth® and Killer™ Bluetooth® products to version 22.100 or later.\r\nWindows 10 and Windows 11 updates are available for download at this location:\r\nhttps://www.intel.com/content/www/us/en/download/18649/intel-wireless-bluetooth-for-windows-10-and-windows-11.html\r\n\xa0\r\nFor the latest Linux updates refer to the links below:\r\nLinux software Driver: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/\r\nLinux firmware: link\r\nProduct Discontinuation Notice:\xa0\r\nIntel has issued a Product Discontinuation Notice for:\r\nIntel® Dual Band Wireless-AC 8265 and Intel® Dual Band Wireless-AC 8260 as of February 2023. The Intel® Dual Band Wireless-AC 8265 and Intel® Dual Band Wireless-AC 8260 are not supported with any additional functional, security, or other updates. Intel recommends that users discontinue use and migrate to the newer generation product listed in Recommendations as soon as possible.Intel® Dual Band Wireless-AC 3168, Intel® Wireless 7265 (Rev D) Family and Intel® Dual Band Wireless-AC 3165 as of April 2024. The Intel® Dual Band Wireless-AC 3168, Intel® Wireless 7265 (Rev D) Family and Intel® Dual Band Wireless-AC 3165 are not supported with any additional functional, security, or other updates. Intel recommends that users discontinue use and migrate to the newer generation product listed in Recommendations as soon as possible.\r\n\r\nReference Documentation:\r\nLinux* Support for Intel® Wireless Adapters: \xa0https://www.intel.com/content/www/us/en/support/articles/000005511/wireless.html', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Wireless Bluetooth® and Killer™ Bluetooth® Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-00606', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2025-02-11T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release.'}], 'current_release_date': '2025-02-11T00:00:00+00:00', 'initial_release_date': '2025-02-11T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00606.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Copyright © Intel Corporation All rights reserved.'}, 'acknowledgments': [{'names': ['This issue was found externally. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2021-37577', 'cwe': {'id': 'CWE-284', 'name': 'Improper Access Control'}, 'title': 'Improper access control in the firmware for some Intel® Wireless Bluetooth® and Killer™ Bluetooth® products before version 22.100 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 4.6, 'attackVector': 'ADJACENT_NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N', 'integrityImpact': 'LOW', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.3, 'attackVector': 'ADJACENT', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'NONE', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'LOW', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'NONE', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'LOW'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-21787
INTEL-SA-00790
BMRA Software Advisory
A potential security vulnerability in some Bare Metal Reference System Architecture (BMRA) software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.
MEDIUM
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00790.html
2275e246c0c4d68336894f7493250f9a35297e69c949062335f6d24ed7c5abeb
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Bare Metal Reference System Architecture (BMRA) software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of BMRA software update to 22.08 or later.\r\nUpdates are available for download at this location:\r\nhttps://github.com/intel/container-experience-kits/releases', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'BMRA Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-00790', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00790.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['This issue was\xa0found internally by Intel. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-21787', 'title': 'Inadequate encryption strength for some BMRA software before version 22.08 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7.1, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-21810
INTEL-SA-00918
Intel® Ethernet Controllers and Adapters Advisory
Potential security vulnerabilities in some Intel® Ethernet Controllers and Adapters may allow escalation of privilege or denial of service. Intel is releasing firmware and software updates to mitigate these potential vulnerabilities.
HIGH
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00918.html
b95964c102f510d624083fcad76298aea32102b9b551d648284cfef675ab8180
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® Ethernet Controllers and Adapters may allow escalation of privilege or denial of service. Intel is releasing firmware and software updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating the software for impacted Intel® Ethernet Controllers and Adapters to the versions provided below or later.\r\n\xa0\r\nUpdate to Intel® Ethernet Complete Driver Pack versions 28.3 or later.\r\nIntel® Ethernet Controllers E800 Series with NVM image versions 4.4 or higher included with Intel® Ethernet Adapter Complete Driver Pack versions 28.3 or higher.\xa0\r\nIntel recommends updating the firmware for impacted Intel® Ethernet Controllers and Adapters to the versions provided below or later.\r\nUpdate firmware to NIC1.3 PV, NVM image version 3.36 or higher included Intel(R) Ethernet Complete Driver Pack versions 28.3 or later.\r\nUpdates are available for download at this location:\xa0\xa0Intel® Ethernet Adapter Complete Driver Pack', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware,software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Ethernet Controllers and Adapters Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-00918', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00918.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['The following issues were found internally by Intel employees: CVE-2024-23981, CVE-2024-21810, CVE-2024-21807, CVE-2024-23497, CVE-and 2024-24986. Intel would like to thank Daniel Medina Velazquez and Thierry Fernandes Faria.\xa0\r\nThe following issues were found internally by Intel employees: CVE-2024-21806, CVE-2024-23499 and CVE-2024-24983.\xa0\r\nIntel would like to thank mohammed for reporting CVE-2024-21769. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-21810', 'title': 'Improper input validation in the Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23497', 'title': 'Out-of-bounds write in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-24983', 'title': 'Protection mechanism failure in firmware for some Intel® Ethernet Network Controllers and Adapters E810 Series before version 4.4 may allow an unauthenticated user to potentially enable denial of service via network access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21807', 'title': 'Improper initialization in the Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23981', 'title': 'Wrap-around error in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23499', 'title': 'Protection mechanism failure in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters E810 Series before version 28.3 may allow an unauthenticated user to potentially enable denial of service via network access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21769', 'title': ' Uncontrolled search path in some Intel® Ethernet Connection I219-LM install software may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-24986', 'title': 'Improper access control in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21806', 'title': 'Improper conditions check in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters E810 Series before version 28.3 may allow an authenticated user to potentially enable denial of service via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-23497
INTEL-SA-00918
Intel® Ethernet Controllers and Adapters Advisory
Potential security vulnerabilities in some Intel® Ethernet Controllers and Adapters may allow escalation of privilege or denial of service. Intel is releasing firmware and software updates to mitigate these potential vulnerabilities.
HIGH
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00918.html
19734a682a497a67d086cb5acd6e4dfea2dd7296c35d2c8f068bfef369859d25
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® Ethernet Controllers and Adapters may allow escalation of privilege or denial of service. Intel is releasing firmware and software updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating the software for impacted Intel® Ethernet Controllers and Adapters to the versions provided below or later.\r\n\xa0\r\nUpdate to Intel® Ethernet Complete Driver Pack versions 28.3 or later.\r\nIntel® Ethernet Controllers E800 Series with NVM image versions 4.4 or higher included with Intel® Ethernet Adapter Complete Driver Pack versions 28.3 or higher.\xa0\r\nIntel recommends updating the firmware for impacted Intel® Ethernet Controllers and Adapters to the versions provided below or later.\r\nUpdate firmware to NIC1.3 PV, NVM image version 3.36 or higher included Intel(R) Ethernet Complete Driver Pack versions 28.3 or later.\r\nUpdates are available for download at this location:\xa0\xa0Intel® Ethernet Adapter Complete Driver Pack', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware,software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Ethernet Controllers and Adapters Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-00918', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00918.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['The following issues were found internally by Intel employees: CVE-2024-23981, CVE-2024-21810, CVE-2024-21807, CVE-2024-23497, CVE-and 2024-24986. Intel would like to thank Daniel Medina Velazquez and Thierry Fernandes Faria.\xa0\r\nThe following issues were found internally by Intel employees: CVE-2024-21806, CVE-2024-23499 and CVE-2024-24983.\xa0\r\nIntel would like to thank mohammed for reporting CVE-2024-21769. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-21810', 'title': 'Improper input validation in the Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23497', 'title': 'Out-of-bounds write in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-24983', 'title': 'Protection mechanism failure in firmware for some Intel® Ethernet Network Controllers and Adapters E810 Series before version 4.4 may allow an unauthenticated user to potentially enable denial of service via network access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21807', 'title': 'Improper initialization in the Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23981', 'title': 'Wrap-around error in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23499', 'title': 'Protection mechanism failure in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters E810 Series before version 28.3 may allow an unauthenticated user to potentially enable denial of service via network access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21769', 'title': ' Uncontrolled search path in some Intel® Ethernet Connection I219-LM install software may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-24986', 'title': 'Improper access control in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21806', 'title': 'Improper conditions check in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters E810 Series before version 28.3 may allow an authenticated user to potentially enable denial of service via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-24983
INTEL-SA-00918
Intel® Ethernet Controllers and Adapters Advisory
Potential security vulnerabilities in some Intel® Ethernet Controllers and Adapters may allow escalation of privilege or denial of service. Intel is releasing firmware and software updates to mitigate these potential vulnerabilities.
HIGH
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00918.html
b6642cc94b65a15687a4ffe6b91de8d622cc0eb04463b293baa4bfa9fae1551b
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® Ethernet Controllers and Adapters may allow escalation of privilege or denial of service. Intel is releasing firmware and software updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating the software for impacted Intel® Ethernet Controllers and Adapters to the versions provided below or later.\r\n\xa0\r\nUpdate to Intel® Ethernet Complete Driver Pack versions 28.3 or later.\r\nIntel® Ethernet Controllers E800 Series with NVM image versions 4.4 or higher included with Intel® Ethernet Adapter Complete Driver Pack versions 28.3 or higher.\xa0\r\nIntel recommends updating the firmware for impacted Intel® Ethernet Controllers and Adapters to the versions provided below or later.\r\nUpdate firmware to NIC1.3 PV, NVM image version 3.36 or higher included Intel(R) Ethernet Complete Driver Pack versions 28.3 or later.\r\nUpdates are available for download at this location:\xa0\xa0Intel® Ethernet Adapter Complete Driver Pack', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware,software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Ethernet Controllers and Adapters Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-00918', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00918.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['The following issues were found internally by Intel employees: CVE-2024-23981, CVE-2024-21810, CVE-2024-21807, CVE-2024-23497, CVE-and 2024-24986. Intel would like to thank Daniel Medina Velazquez and Thierry Fernandes Faria.\xa0\r\nThe following issues were found internally by Intel employees: CVE-2024-21806, CVE-2024-23499 and CVE-2024-24983.\xa0\r\nIntel would like to thank mohammed for reporting CVE-2024-21769. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-21810', 'title': 'Improper input validation in the Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23497', 'title': 'Out-of-bounds write in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-24983', 'title': 'Protection mechanism failure in firmware for some Intel® Ethernet Network Controllers and Adapters E810 Series before version 4.4 may allow an unauthenticated user to potentially enable denial of service via network access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21807', 'title': 'Improper initialization in the Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23981', 'title': 'Wrap-around error in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23499', 'title': 'Protection mechanism failure in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters E810 Series before version 28.3 may allow an unauthenticated user to potentially enable denial of service via network access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21769', 'title': ' Uncontrolled search path in some Intel® Ethernet Connection I219-LM install software may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-24986', 'title': 'Improper access control in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21806', 'title': 'Improper conditions check in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters E810 Series before version 28.3 may allow an authenticated user to potentially enable denial of service via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2025-20097
INTEL-SA-00990
Intel® Server Board BMC Firmware Advisory
Potential security vulnerabilities in some Intel® Server Board BMC Firmware may allow escalation of privilege, information disclosure or denial of service. Intel is releasing firmware updates to mitigate these potential vulnerabilities.
MEDIUM
2025-02-11 03:00:00+03:00
2025-02-11 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00990.html
8a5b4a9ea6d887dd051e150eda777cb06ed6c9debdf91547292cf9b34b603e9c
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® Server Board BMC Firmware may allow escalation of privilege, information disclosure or denial of service. Intel is releasing firmware updates to mitigate these potential vulnerabilities.\r\n', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Updates for Intel® Server Board S2600WF Family can be found here.\r\nUpdates for Intel® Server Board S2600ST Family can be found here.\r\nUpdates for Intel® Server Board S2600BP Family can be found here. \xa0\r\nUpdates for Intel® Server Board M70KLP Family BMC Firmware can be found\xa0here.\r\nUpdates for Intel® Server M20NTP Family BMC Firmware can be found\xa0here.\r\nUpdates for Intel® Server Board M10JNP Family BMC Firmware can be found\xa0here.\xa0\r\nUpdates for Intel® Server Board M50CYP Family can be found here.\r\nUpdates for Intel® Server Board D50TNP Family can be found here.\xa0\r\nUpdates for Intel® Server M50FCP Family can be found here.\r\nUpdates for Intel® Server Board D50DNP Family can be found here.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Critical', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Server Board BMC Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-00990', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2025-02-11T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2025-02-11T00:00:00+00:00', 'initial_release_date': '2025-02-11T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00990.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Copyright © Intel Corporation All rights reserved.'}, 'acknowledgments': [{'names': ['CVE-2023-25191, CVE-2023-25192 were found internally by Intel employees. Intel would like to thank Alex Gutkin and Ignacio Hernandez.\xa0\r\nCVE-2023-31276 was found internally by Intel employees. Intel would like to thank Daniel Medina Velazquez and Thierry Fernandes Faria.\xa0\r\nCVE-2023-29164 was found internally by Intel employees. Intel would like to thank Tal Rosen, Benny Zeltser and Rami Sudai. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2025-20097', 'cwe': {'id': 'CWE-703', 'name': 'Improper Check or Handling of Exceptional Conditions'}, 'title': 'Uncaught exception in OpenBMC Firmware for the Intel® Server M50FCP Family and Intel® Server D50DNP Family before version R01.02.0002 may allow an authenticated user to potentially enable denial of service via network access. ', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 4.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'NONE', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'LOW', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'NONE'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-25191', 'cwe': {'id': 'CWE-284', 'name': 'Improper Access Control'}, 'title': 'Improper access control in AMI BMC firmware for the Intel® Server Board M70KLP, Intel® Server M20NTP, and Intel® Server Board M10JNP before versions 4.16, 0027.D02 and 7.220 may allow an unauthenticated user to enable escalation of privilege via network access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.1, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'NONE', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'NONE', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-25192', 'cwe': {'id': 'CWE-522', 'name': 'Insufficiently Protected Credentials'}, 'title': 'Insufficiently protected credentials in AMI BMC firmware for Intel® Server Board M70KLP, Intel® Server M20NTP, and Intel® Server Board M10JNP products before before versions 4.16, 0027.D02 and 7.220 may allow an unauthenticated user to enable information disclosure via network access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N', 'userInteraction': 'PASSIVE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'NONE', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'NONE', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'NONE', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'LOW'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-29164', 'cwe': {'id': 'CWE-862', 'name': 'Missing Authorization'}, 'title': 'Improper access control in BMC Firmware for the Intel® Server Board S2600WF, Intel® Server Board S2600ST, Intel® Server Board S2600BP, before version 02.01.0017 and Intel® Server Board M50CYP and Intel® Server Board D50TNP before version R01.01.0009 may allow an authenticated user to enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 7.3, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'LOW'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.8, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'NONE', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'LOW'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-31276', 'cwe': {'id': 'CWE-122', 'name': 'Heap-based Buffer Overflow'}, 'title': 'Heap-based buffer overflow in BMC Firmware for the Intel® Server Board S2600WF, Intel® Server Board S2600ST, Intel® Server Board S2600BP, before version 02.01.0017 and Intel® Server Board M50CYP and Intel® Server Board D50TNP before version R01.01.0009 may allow a privileged user to enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 8.2, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'HIGH', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.4, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'HIGH', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'HIGH', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2023-25191
INTEL-SA-00990
Intel® Server Board BMC Firmware Advisory
Potential security vulnerabilities in some Intel® Server Board BMC Firmware may allow escalation of privilege, information disclosure or denial of service. Intel is releasing firmware updates to mitigate these potential vulnerabilities.
MEDIUM
2025-02-11 03:00:00+03:00
2025-02-11 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00990.html
ab0f1e889efc0e40e820ba0d03bf33e112ed3c7ac286bbea4e97ff23c1d7d931
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® Server Board BMC Firmware may allow escalation of privilege, information disclosure or denial of service. Intel is releasing firmware updates to mitigate these potential vulnerabilities.\r\n', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Updates for Intel® Server Board S2600WF Family can be found here.\r\nUpdates for Intel® Server Board S2600ST Family can be found here.\r\nUpdates for Intel® Server Board S2600BP Family can be found here. \xa0\r\nUpdates for Intel® Server Board M70KLP Family BMC Firmware can be found\xa0here.\r\nUpdates for Intel® Server M20NTP Family BMC Firmware can be found\xa0here.\r\nUpdates for Intel® Server Board M10JNP Family BMC Firmware can be found\xa0here.\xa0\r\nUpdates for Intel® Server Board M50CYP Family can be found here.\r\nUpdates for Intel® Server Board D50TNP Family can be found here.\xa0\r\nUpdates for Intel® Server M50FCP Family can be found here.\r\nUpdates for Intel® Server Board D50DNP Family can be found here.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Critical', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Server Board BMC Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-00990', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2025-02-11T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2025-02-11T00:00:00+00:00', 'initial_release_date': '2025-02-11T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00990.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Copyright © Intel Corporation All rights reserved.'}, 'acknowledgments': [{'names': ['CVE-2023-25191, CVE-2023-25192 were found internally by Intel employees. Intel would like to thank Alex Gutkin and Ignacio Hernandez.\xa0\r\nCVE-2023-31276 was found internally by Intel employees. Intel would like to thank Daniel Medina Velazquez and Thierry Fernandes Faria.\xa0\r\nCVE-2023-29164 was found internally by Intel employees. Intel would like to thank Tal Rosen, Benny Zeltser and Rami Sudai. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2025-20097', 'cwe': {'id': 'CWE-703', 'name': 'Improper Check or Handling of Exceptional Conditions'}, 'title': 'Uncaught exception in OpenBMC Firmware for the Intel® Server M50FCP Family and Intel® Server D50DNP Family before version R01.02.0002 may allow an authenticated user to potentially enable denial of service via network access. ', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 4.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'NONE', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'LOW', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'NONE'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-25191', 'cwe': {'id': 'CWE-284', 'name': 'Improper Access Control'}, 'title': 'Improper access control in AMI BMC firmware for the Intel® Server Board M70KLP, Intel® Server M20NTP, and Intel® Server Board M10JNP before versions 4.16, 0027.D02 and 7.220 may allow an unauthenticated user to enable escalation of privilege via network access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.1, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'NONE', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'NONE', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-25192', 'cwe': {'id': 'CWE-522', 'name': 'Insufficiently Protected Credentials'}, 'title': 'Insufficiently protected credentials in AMI BMC firmware for Intel® Server Board M70KLP, Intel® Server M20NTP, and Intel® Server Board M10JNP products before before versions 4.16, 0027.D02 and 7.220 may allow an unauthenticated user to enable information disclosure via network access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N', 'userInteraction': 'PASSIVE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'NONE', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'NONE', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'NONE', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'LOW'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-29164', 'cwe': {'id': 'CWE-862', 'name': 'Missing Authorization'}, 'title': 'Improper access control in BMC Firmware for the Intel® Server Board S2600WF, Intel® Server Board S2600ST, Intel® Server Board S2600BP, before version 02.01.0017 and Intel® Server Board M50CYP and Intel® Server Board D50TNP before version R01.01.0009 may allow an authenticated user to enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 7.3, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'LOW'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.8, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'NONE', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'LOW'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-31276', 'cwe': {'id': 'CWE-122', 'name': 'Heap-based Buffer Overflow'}, 'title': 'Heap-based buffer overflow in BMC Firmware for the Intel® Server Board S2600WF, Intel® Server Board S2600ST, Intel® Server Board S2600BP, before version 02.01.0017 and Intel® Server Board M50CYP and Intel® Server Board D50TNP before version R01.01.0009 may allow a privileged user to enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 8.2, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'HIGH', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.4, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'HIGH', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'HIGH', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2023-25192
INTEL-SA-00990
Intel® Server Board BMC Firmware Advisory
Potential security vulnerabilities in some Intel® Server Board BMC Firmware may allow escalation of privilege, information disclosure or denial of service. Intel is releasing firmware updates to mitigate these potential vulnerabilities.
MEDIUM
2025-02-11 03:00:00+03:00
2025-02-11 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00990.html
115c71fcad171e00ea416b2a7bbaac1c948b78e9b52d852af710cb3fddb78484
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® Server Board BMC Firmware may allow escalation of privilege, information disclosure or denial of service. Intel is releasing firmware updates to mitigate these potential vulnerabilities.\r\n', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Updates for Intel® Server Board S2600WF Family can be found here.\r\nUpdates for Intel® Server Board S2600ST Family can be found here.\r\nUpdates for Intel® Server Board S2600BP Family can be found here. \xa0\r\nUpdates for Intel® Server Board M70KLP Family BMC Firmware can be found\xa0here.\r\nUpdates for Intel® Server M20NTP Family BMC Firmware can be found\xa0here.\r\nUpdates for Intel® Server Board M10JNP Family BMC Firmware can be found\xa0here.\xa0\r\nUpdates for Intel® Server Board M50CYP Family can be found here.\r\nUpdates for Intel® Server Board D50TNP Family can be found here.\xa0\r\nUpdates for Intel® Server M50FCP Family can be found here.\r\nUpdates for Intel® Server Board D50DNP Family can be found here.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Critical', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Server Board BMC Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-00990', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2025-02-11T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2025-02-11T00:00:00+00:00', 'initial_release_date': '2025-02-11T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00990.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Copyright © Intel Corporation All rights reserved.'}, 'acknowledgments': [{'names': ['CVE-2023-25191, CVE-2023-25192 were found internally by Intel employees. Intel would like to thank Alex Gutkin and Ignacio Hernandez.\xa0\r\nCVE-2023-31276 was found internally by Intel employees. Intel would like to thank Daniel Medina Velazquez and Thierry Fernandes Faria.\xa0\r\nCVE-2023-29164 was found internally by Intel employees. Intel would like to thank Tal Rosen, Benny Zeltser and Rami Sudai. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2025-20097', 'cwe': {'id': 'CWE-703', 'name': 'Improper Check or Handling of Exceptional Conditions'}, 'title': 'Uncaught exception in OpenBMC Firmware for the Intel® Server M50FCP Family and Intel® Server D50DNP Family before version R01.02.0002 may allow an authenticated user to potentially enable denial of service via network access. ', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 4.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'NONE', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'LOW', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'NONE'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-25191', 'cwe': {'id': 'CWE-284', 'name': 'Improper Access Control'}, 'title': 'Improper access control in AMI BMC firmware for the Intel® Server Board M70KLP, Intel® Server M20NTP, and Intel® Server Board M10JNP before versions 4.16, 0027.D02 and 7.220 may allow an unauthenticated user to enable escalation of privilege via network access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.1, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'NONE', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'NONE', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-25192', 'cwe': {'id': 'CWE-522', 'name': 'Insufficiently Protected Credentials'}, 'title': 'Insufficiently protected credentials in AMI BMC firmware for Intel® Server Board M70KLP, Intel® Server M20NTP, and Intel® Server Board M10JNP products before before versions 4.16, 0027.D02 and 7.220 may allow an unauthenticated user to enable information disclosure via network access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N', 'userInteraction': 'PASSIVE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'NONE', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'NONE', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'NONE', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'LOW'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-29164', 'cwe': {'id': 'CWE-862', 'name': 'Missing Authorization'}, 'title': 'Improper access control in BMC Firmware for the Intel® Server Board S2600WF, Intel® Server Board S2600ST, Intel® Server Board S2600BP, before version 02.01.0017 and Intel® Server Board M50CYP and Intel® Server Board D50TNP before version R01.01.0009 may allow an authenticated user to enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 7.3, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'LOW'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.8, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'NONE', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'LOW'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-31276', 'cwe': {'id': 'CWE-122', 'name': 'Heap-based Buffer Overflow'}, 'title': 'Heap-based buffer overflow in BMC Firmware for the Intel® Server Board S2600WF, Intel® Server Board S2600ST, Intel® Server Board S2600BP, before version 02.01.0017 and Intel® Server Board M50CYP and Intel® Server Board D50TNP before version R01.01.0009 may allow a privileged user to enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 8.2, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'HIGH', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.4, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'HIGH', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'HIGH', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2023-29164
INTEL-SA-00990
Intel® Server Board BMC Firmware Advisory
Potential security vulnerabilities in some Intel® Server Board BMC Firmware may allow escalation of privilege, information disclosure or denial of service. Intel is releasing firmware updates to mitigate these potential vulnerabilities.
MEDIUM
2025-02-11 03:00:00+03:00
2025-02-11 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00990.html
0c2efeffb59da7020c571f160c74b8b704c9c2add020a151b3174c026de9ba95
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® Server Board BMC Firmware may allow escalation of privilege, information disclosure or denial of service. Intel is releasing firmware updates to mitigate these potential vulnerabilities.\r\n', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Updates for Intel® Server Board S2600WF Family can be found here.\r\nUpdates for Intel® Server Board S2600ST Family can be found here.\r\nUpdates for Intel® Server Board S2600BP Family can be found here. \xa0\r\nUpdates for Intel® Server Board M70KLP Family BMC Firmware can be found\xa0here.\r\nUpdates for Intel® Server M20NTP Family BMC Firmware can be found\xa0here.\r\nUpdates for Intel® Server Board M10JNP Family BMC Firmware can be found\xa0here.\xa0\r\nUpdates for Intel® Server Board M50CYP Family can be found here.\r\nUpdates for Intel® Server Board D50TNP Family can be found here.\xa0\r\nUpdates for Intel® Server M50FCP Family can be found here.\r\nUpdates for Intel® Server Board D50DNP Family can be found here.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Critical', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Server Board BMC Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-00990', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2025-02-11T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2025-02-11T00:00:00+00:00', 'initial_release_date': '2025-02-11T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00990.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Copyright © Intel Corporation All rights reserved.'}, 'acknowledgments': [{'names': ['CVE-2023-25191, CVE-2023-25192 were found internally by Intel employees. Intel would like to thank Alex Gutkin and Ignacio Hernandez.\xa0\r\nCVE-2023-31276 was found internally by Intel employees. Intel would like to thank Daniel Medina Velazquez and Thierry Fernandes Faria.\xa0\r\nCVE-2023-29164 was found internally by Intel employees. Intel would like to thank Tal Rosen, Benny Zeltser and Rami Sudai. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2025-20097', 'cwe': {'id': 'CWE-703', 'name': 'Improper Check or Handling of Exceptional Conditions'}, 'title': 'Uncaught exception in OpenBMC Firmware for the Intel® Server M50FCP Family and Intel® Server D50DNP Family before version R01.02.0002 may allow an authenticated user to potentially enable denial of service via network access. ', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 4.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'NONE', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'LOW', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'NONE'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-25191', 'cwe': {'id': 'CWE-284', 'name': 'Improper Access Control'}, 'title': 'Improper access control in AMI BMC firmware for the Intel® Server Board M70KLP, Intel® Server M20NTP, and Intel® Server Board M10JNP before versions 4.16, 0027.D02 and 7.220 may allow an unauthenticated user to enable escalation of privilege via network access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.1, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'NONE', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'NONE', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-25192', 'cwe': {'id': 'CWE-522', 'name': 'Insufficiently Protected Credentials'}, 'title': 'Insufficiently protected credentials in AMI BMC firmware for Intel® Server Board M70KLP, Intel® Server M20NTP, and Intel® Server Board M10JNP products before before versions 4.16, 0027.D02 and 7.220 may allow an unauthenticated user to enable information disclosure via network access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N', 'userInteraction': 'PASSIVE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'NONE', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'NONE', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'NONE', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'LOW'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-29164', 'cwe': {'id': 'CWE-862', 'name': 'Missing Authorization'}, 'title': 'Improper access control in BMC Firmware for the Intel® Server Board S2600WF, Intel® Server Board S2600ST, Intel® Server Board S2600BP, before version 02.01.0017 and Intel® Server Board M50CYP and Intel® Server Board D50TNP before version R01.01.0009 may allow an authenticated user to enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 7.3, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'LOW'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.8, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'NONE', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'LOW'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-31276', 'cwe': {'id': 'CWE-122', 'name': 'Heap-based Buffer Overflow'}, 'title': 'Heap-based buffer overflow in BMC Firmware for the Intel® Server Board S2600WF, Intel® Server Board S2600ST, Intel® Server Board S2600BP, before version 02.01.0017 and Intel® Server Board M50CYP and Intel® Server Board D50TNP before version R01.01.0009 may allow a privileged user to enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 8.2, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'HIGH', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.4, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'HIGH', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'HIGH', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2023-31276
INTEL-SA-00990
Intel® Server Board BMC Firmware Advisory
Potential security vulnerabilities in some Intel® Server Board BMC Firmware may allow escalation of privilege, information disclosure or denial of service. Intel is releasing firmware updates to mitigate these potential vulnerabilities.
MEDIUM
2025-02-11 03:00:00+03:00
2025-02-11 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00990.html
3064593547288add6d0b9ccb760bfc9c45f7022d058770105343e695e64bb9b1
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® Server Board BMC Firmware may allow escalation of privilege, information disclosure or denial of service. Intel is releasing firmware updates to mitigate these potential vulnerabilities.\r\n', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Updates for Intel® Server Board S2600WF Family can be found here.\r\nUpdates for Intel® Server Board S2600ST Family can be found here.\r\nUpdates for Intel® Server Board S2600BP Family can be found here. \xa0\r\nUpdates for Intel® Server Board M70KLP Family BMC Firmware can be found\xa0here.\r\nUpdates for Intel® Server M20NTP Family BMC Firmware can be found\xa0here.\r\nUpdates for Intel® Server Board M10JNP Family BMC Firmware can be found\xa0here.\xa0\r\nUpdates for Intel® Server Board M50CYP Family can be found here.\r\nUpdates for Intel® Server Board D50TNP Family can be found here.\xa0\r\nUpdates for Intel® Server M50FCP Family can be found here.\r\nUpdates for Intel® Server Board D50DNP Family can be found here.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Critical', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Server Board BMC Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-00990', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2025-02-11T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2025-02-11T00:00:00+00:00', 'initial_release_date': '2025-02-11T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00990.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Copyright © Intel Corporation All rights reserved.'}, 'acknowledgments': [{'names': ['CVE-2023-25191, CVE-2023-25192 were found internally by Intel employees. Intel would like to thank Alex Gutkin and Ignacio Hernandez.\xa0\r\nCVE-2023-31276 was found internally by Intel employees. Intel would like to thank Daniel Medina Velazquez and Thierry Fernandes Faria.\xa0\r\nCVE-2023-29164 was found internally by Intel employees. Intel would like to thank Tal Rosen, Benny Zeltser and Rami Sudai. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2025-20097', 'cwe': {'id': 'CWE-703', 'name': 'Improper Check or Handling of Exceptional Conditions'}, 'title': 'Uncaught exception in OpenBMC Firmware for the Intel® Server M50FCP Family and Intel® Server D50DNP Family before version R01.02.0002 may allow an authenticated user to potentially enable denial of service via network access. ', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 4.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'NONE', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'LOW', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'NONE'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-25191', 'cwe': {'id': 'CWE-284', 'name': 'Improper Access Control'}, 'title': 'Improper access control in AMI BMC firmware for the Intel® Server Board M70KLP, Intel® Server M20NTP, and Intel® Server Board M10JNP before versions 4.16, 0027.D02 and 7.220 may allow an unauthenticated user to enable escalation of privilege via network access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.1, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'NONE', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'NONE', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-25192', 'cwe': {'id': 'CWE-522', 'name': 'Insufficiently Protected Credentials'}, 'title': 'Insufficiently protected credentials in AMI BMC firmware for Intel® Server Board M70KLP, Intel® Server M20NTP, and Intel® Server Board M10JNP products before before versions 4.16, 0027.D02 and 7.220 may allow an unauthenticated user to enable information disclosure via network access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N', 'userInteraction': 'PASSIVE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'NONE', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'NONE', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'NONE', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'LOW'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-29164', 'cwe': {'id': 'CWE-862', 'name': 'Missing Authorization'}, 'title': 'Improper access control in BMC Firmware for the Intel® Server Board S2600WF, Intel® Server Board S2600ST, Intel® Server Board S2600BP, before version 02.01.0017 and Intel® Server Board M50CYP and Intel® Server Board D50TNP before version R01.01.0009 may allow an authenticated user to enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 7.3, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'LOW'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.8, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'NONE', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'LOW'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-31276', 'cwe': {'id': 'CWE-122', 'name': 'Heap-based Buffer Overflow'}, 'title': 'Heap-based buffer overflow in BMC Firmware for the Intel® Server Board S2600WF, Intel® Server Board S2600ST, Intel® Server Board S2600BP, before version 02.01.0017 and Intel® Server Board M50CYP and Intel® Server Board D50TNP before version R01.01.0009 may allow a privileged user to enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 8.2, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'HIGH', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.4, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'HIGH', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'HIGH', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2023-34424
INTEL-SA-00999
2024.3 IPU - Intel® Chipset Firmware Advisory
Potential security vulnerabilities in Intel® Converged Security and Manageability Engine (CSME), Intel® Active Management Technology (AMT), Intel® Standard Manageability, Intel® PROSet/Wireless and Intel® Killer™ Wi-Fi software may allow escalation of privilege, denial of service, or information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities.
MEDIUM
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00999.html
25fb71e2d9a67c68776ad01337b9e5c0aa7a3dd6ab890663a58043fbbcd31381
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in Intel® Converged Security and Manageability Engine (CSME), Intel® Active Management Technology (AMT), Intel® Standard Manageability, Intel® PROSet/Wireless and Intel® Killer™ Wi-Fi software may allow escalation of privilege, denial of service, or information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of Intel® Converged Security and Manageability Engine (CSME), Intel® Active Management Technology (AMT), Intel® Standard Manageability, Intel® PROSet/Wireless and Intel® Killer™ Wi-Fi software\xa0 update to the latest version provided by the system manufacturer that addresses these issues.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': '2024.3 IPU - Intel® Chipset Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-00999', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00999.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['The following issues were found internally by Intel Employees.\xa0 Intel would like to thank Alexander Kantor and Ora Naki (CVE-2023-40067), Igor Metric (CVE-2024-21844), Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-34424', 'title': 'Improper input validation in firmware for some Intel® CSME may allow a privileged user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-38655', 'title': 'Improper buffer restrictions in firmware for some Intel® AMT and Intel® Standard Manageability may allow a privileged user to potentially enable denial of service via network access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-35061', 'title': 'Improper initialization for the Intel® PROSet/Wireless and Intel® Killer™ Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable information disclosure via adjacent access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 2.3, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21844', 'title': 'Integer overflow in firmware for some Intel® CSME may allow an unauthenticated user to potentially enable denial of service via adjacent access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-40067', 'title': 'Unchecked return value in firmware for some Intel® CSME may allow an unauthenticated user to potentially enable escalation of privilege via physical access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:P/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:L/SI:H/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-48361', 'title': 'Improper initialization in firmware for some Intel® CSME may allow a privileged user to potentially enable information disclosure via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 2.3, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 4.6, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2023-38655
INTEL-SA-00999
2024.3 IPU - Intel® Chipset Firmware Advisory
Potential security vulnerabilities in Intel® Converged Security and Manageability Engine (CSME), Intel® Active Management Technology (AMT), Intel® Standard Manageability, Intel® PROSet/Wireless and Intel® Killer™ Wi-Fi software may allow escalation of privilege, denial of service, or information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities.
MEDIUM
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00999.html
cd70f6b7a142b2c7b2af58579292a96d1c2edb1d7c096e31e342f4724205b647
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in Intel® Converged Security and Manageability Engine (CSME), Intel® Active Management Technology (AMT), Intel® Standard Manageability, Intel® PROSet/Wireless and Intel® Killer™ Wi-Fi software may allow escalation of privilege, denial of service, or information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of Intel® Converged Security and Manageability Engine (CSME), Intel® Active Management Technology (AMT), Intel® Standard Manageability, Intel® PROSet/Wireless and Intel® Killer™ Wi-Fi software\xa0 update to the latest version provided by the system manufacturer that addresses these issues.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': '2024.3 IPU - Intel® Chipset Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-00999', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00999.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['The following issues were found internally by Intel Employees.\xa0 Intel would like to thank Alexander Kantor and Ora Naki (CVE-2023-40067), Igor Metric (CVE-2024-21844), Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-34424', 'title': 'Improper input validation in firmware for some Intel® CSME may allow a privileged user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-38655', 'title': 'Improper buffer restrictions in firmware for some Intel® AMT and Intel® Standard Manageability may allow a privileged user to potentially enable denial of service via network access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-35061', 'title': 'Improper initialization for the Intel® PROSet/Wireless and Intel® Killer™ Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable information disclosure via adjacent access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 2.3, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21844', 'title': 'Integer overflow in firmware for some Intel® CSME may allow an unauthenticated user to potentially enable denial of service via adjacent access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-40067', 'title': 'Unchecked return value in firmware for some Intel® CSME may allow an unauthenticated user to potentially enable escalation of privilege via physical access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:P/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:L/SI:H/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-48361', 'title': 'Improper initialization in firmware for some Intel® CSME may allow a privileged user to potentially enable information disclosure via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 2.3, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 4.6, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2023-35061
INTEL-SA-00999
2024.3 IPU - Intel® Chipset Firmware Advisory
Potential security vulnerabilities in Intel® Converged Security and Manageability Engine (CSME), Intel® Active Management Technology (AMT), Intel® Standard Manageability, Intel® PROSet/Wireless and Intel® Killer™ Wi-Fi software may allow escalation of privilege, denial of service, or information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities.
MEDIUM
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00999.html
6064a0584d56804d9c53a9cf73eaf0bad1c5963103340a511ff2fb1740a76c08
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in Intel® Converged Security and Manageability Engine (CSME), Intel® Active Management Technology (AMT), Intel® Standard Manageability, Intel® PROSet/Wireless and Intel® Killer™ Wi-Fi software may allow escalation of privilege, denial of service, or information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of Intel® Converged Security and Manageability Engine (CSME), Intel® Active Management Technology (AMT), Intel® Standard Manageability, Intel® PROSet/Wireless and Intel® Killer™ Wi-Fi software\xa0 update to the latest version provided by the system manufacturer that addresses these issues.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': '2024.3 IPU - Intel® Chipset Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-00999', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00999.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['The following issues were found internally by Intel Employees.\xa0 Intel would like to thank Alexander Kantor and Ora Naki (CVE-2023-40067), Igor Metric (CVE-2024-21844), Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-34424', 'title': 'Improper input validation in firmware for some Intel® CSME may allow a privileged user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-38655', 'title': 'Improper buffer restrictions in firmware for some Intel® AMT and Intel® Standard Manageability may allow a privileged user to potentially enable denial of service via network access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-35061', 'title': 'Improper initialization for the Intel® PROSet/Wireless and Intel® Killer™ Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable information disclosure via adjacent access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 2.3, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21844', 'title': 'Integer overflow in firmware for some Intel® CSME may allow an unauthenticated user to potentially enable denial of service via adjacent access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-40067', 'title': 'Unchecked return value in firmware for some Intel® CSME may allow an unauthenticated user to potentially enable escalation of privilege via physical access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:P/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:L/SI:H/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-48361', 'title': 'Improper initialization in firmware for some Intel® CSME may allow a privileged user to potentially enable information disclosure via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 2.3, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 4.6, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-21844
INTEL-SA-00999
2024.3 IPU - Intel® Chipset Firmware Advisory
Potential security vulnerabilities in Intel® Converged Security and Manageability Engine (CSME), Intel® Active Management Technology (AMT), Intel® Standard Manageability, Intel® PROSet/Wireless and Intel® Killer™ Wi-Fi software may allow escalation of privilege, denial of service, or information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities.
MEDIUM
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00999.html
7c9a91fa2c95fe2630bf29096ea412dff9459bf728b349dd8287cb22e789aab2
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in Intel® Converged Security and Manageability Engine (CSME), Intel® Active Management Technology (AMT), Intel® Standard Manageability, Intel® PROSet/Wireless and Intel® Killer™ Wi-Fi software may allow escalation of privilege, denial of service, or information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of Intel® Converged Security and Manageability Engine (CSME), Intel® Active Management Technology (AMT), Intel® Standard Manageability, Intel® PROSet/Wireless and Intel® Killer™ Wi-Fi software\xa0 update to the latest version provided by the system manufacturer that addresses these issues.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': '2024.3 IPU - Intel® Chipset Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-00999', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00999.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['The following issues were found internally by Intel Employees.\xa0 Intel would like to thank Alexander Kantor and Ora Naki (CVE-2023-40067), Igor Metric (CVE-2024-21844), Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-34424', 'title': 'Improper input validation in firmware for some Intel® CSME may allow a privileged user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-38655', 'title': 'Improper buffer restrictions in firmware for some Intel® AMT and Intel® Standard Manageability may allow a privileged user to potentially enable denial of service via network access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-35061', 'title': 'Improper initialization for the Intel® PROSet/Wireless and Intel® Killer™ Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable information disclosure via adjacent access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 2.3, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21844', 'title': 'Integer overflow in firmware for some Intel® CSME may allow an unauthenticated user to potentially enable denial of service via adjacent access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-40067', 'title': 'Unchecked return value in firmware for some Intel® CSME may allow an unauthenticated user to potentially enable escalation of privilege via physical access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:P/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:L/SI:H/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-48361', 'title': 'Improper initialization in firmware for some Intel® CSME may allow a privileged user to potentially enable information disclosure via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 2.3, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 4.6, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2023-40067
INTEL-SA-00999
2024.3 IPU - Intel® Chipset Firmware Advisory
Potential security vulnerabilities in Intel® Converged Security and Manageability Engine (CSME), Intel® Active Management Technology (AMT), Intel® Standard Manageability, Intel® PROSet/Wireless and Intel® Killer™ Wi-Fi software may allow escalation of privilege, denial of service, or information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities.
MEDIUM
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00999.html
64cfd921f7e6df9e26a5e688f96b222a90f37d93b6bffce0b4d1f8f675187077
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in Intel® Converged Security and Manageability Engine (CSME), Intel® Active Management Technology (AMT), Intel® Standard Manageability, Intel® PROSet/Wireless and Intel® Killer™ Wi-Fi software may allow escalation of privilege, denial of service, or information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of Intel® Converged Security and Manageability Engine (CSME), Intel® Active Management Technology (AMT), Intel® Standard Manageability, Intel® PROSet/Wireless and Intel® Killer™ Wi-Fi software\xa0 update to the latest version provided by the system manufacturer that addresses these issues.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': '2024.3 IPU - Intel® Chipset Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-00999', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00999.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['The following issues were found internally by Intel Employees.\xa0 Intel would like to thank Alexander Kantor and Ora Naki (CVE-2023-40067), Igor Metric (CVE-2024-21844), Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-34424', 'title': 'Improper input validation in firmware for some Intel® CSME may allow a privileged user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-38655', 'title': 'Improper buffer restrictions in firmware for some Intel® AMT and Intel® Standard Manageability may allow a privileged user to potentially enable denial of service via network access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-35061', 'title': 'Improper initialization for the Intel® PROSet/Wireless and Intel® Killer™ Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable information disclosure via adjacent access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 2.3, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21844', 'title': 'Integer overflow in firmware for some Intel® CSME may allow an unauthenticated user to potentially enable denial of service via adjacent access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-40067', 'title': 'Unchecked return value in firmware for some Intel® CSME may allow an unauthenticated user to potentially enable escalation of privilege via physical access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:P/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:L/SI:H/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-48361', 'title': 'Improper initialization in firmware for some Intel® CSME may allow a privileged user to potentially enable information disclosure via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 2.3, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 4.6, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2023-48361
INTEL-SA-00999
2024.3 IPU - Intel® Chipset Firmware Advisory
Potential security vulnerabilities in Intel® Converged Security and Manageability Engine (CSME), Intel® Active Management Technology (AMT), Intel® Standard Manageability, Intel® PROSet/Wireless and Intel® Killer™ Wi-Fi software may allow escalation of privilege, denial of service, or information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities.
MEDIUM
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00999.html
77631556cded0cd56921a70b43241178465da02667ae1676ebe664b5b5cf69bd
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in Intel® Converged Security and Manageability Engine (CSME), Intel® Active Management Technology (AMT), Intel® Standard Manageability, Intel® PROSet/Wireless and Intel® Killer™ Wi-Fi software may allow escalation of privilege, denial of service, or information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of Intel® Converged Security and Manageability Engine (CSME), Intel® Active Management Technology (AMT), Intel® Standard Manageability, Intel® PROSet/Wireless and Intel® Killer™ Wi-Fi software\xa0 update to the latest version provided by the system manufacturer that addresses these issues.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': '2024.3 IPU - Intel® Chipset Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-00999', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00999.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['The following issues were found internally by Intel Employees.\xa0 Intel would like to thank Alexander Kantor and Ora Naki (CVE-2023-40067), Igor Metric (CVE-2024-21844), Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-34424', 'title': 'Improper input validation in firmware for some Intel® CSME may allow a privileged user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-38655', 'title': 'Improper buffer restrictions in firmware for some Intel® AMT and Intel® Standard Manageability may allow a privileged user to potentially enable denial of service via network access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-35061', 'title': 'Improper initialization for the Intel® PROSet/Wireless and Intel® Killer™ Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable information disclosure via adjacent access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 2.3, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21844', 'title': 'Integer overflow in firmware for some Intel® CSME may allow an unauthenticated user to potentially enable denial of service via adjacent access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-40067', 'title': 'Unchecked return value in firmware for some Intel® CSME may allow an unauthenticated user to potentially enable escalation of privilege via physical access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:P/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:L/SI:H/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-48361', 'title': 'Improper initialization in firmware for some Intel® CSME may allow a privileged user to potentially enable information disclosure via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 2.3, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 4.6, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-39283
INTEL-SA-01010
Intel® TDX Module Software Advisory
A potential security vulnerability in Intel® Trust Domain Extensions (TDX) module software may allow escalation of privilege. Intel is releasing firmware updates to mitigate this potential vulnerability.
MEDIUM
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01010.html
947fdd10dcf92d7394db7010bb518d95a3dae6d08d560fea9397a41756fc279f
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in Intel® Trust Domain Extensions (TDX) module software may allow escalation of privilege. Intel is releasing firmware updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating the TDX module software to version TDX 1.5.01.02.595 or later.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® TDX Module Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01010', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01010.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank Maxime Villard from Microsoft for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-39283', 'title': 'Incomplete filtering of special elements in Intel® TDX module software before version TDX_1.5.01.00.592 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2023-45229
INTEL-SA-01022
Intel® NUC BIOS Firmware Advisory
Potential security vulnerabilities in some Intel® NUC BIOS Firmware may allow escalation of privilege, denial of service, information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities.
MEDIUM
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01022.html
dde43b5ce3cec4f159acc5fb7858b966c62cf5244198f07874d08cb6c85f3dc0
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® NUC BIOS Firmware may allow escalation of privilege, denial of service, information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating the affected Intel® NUC BIOS firmware to the latest version\xa0\r\n\r\nIntel® NUC X15 Laptop Kits\r\n\r\nDownload Link\r\n\r\nLAPAC71G, LAPAC71H\r\n\r\nACADL357.0065\r\n\r\nLAPBC510, LAPBC710\r\n\r\nBCTGL357.0083\r\n\r\nLAPRC510, LAPRC710\r\n\r\nRCADL357.0066\r\n\r\nLAPKC51E, LAPKC71E, LAPKC71F\r\n\r\nKCTGL357.0048', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® NUC BIOS Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01022', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01022.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank Yngweijw\xa0 (CVE-2024-34163) for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-45229', 'title': "EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing the IA_NA or IA_TA option in a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2022-36763', 'title': 'EDK2 is susceptible to a vulnerability in the Tcg2MeasureGptTable() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45231', 'title': "EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing Neighbor Discovery Redirect message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45232', 'title': "EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45237', 'title': "EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45235', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability when handling Server ID option from a DHCPv6 proxy Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45230', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability via a long server ID option in DHCPv6 client. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45236', 'title': "EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-34163', 'title': 'Improper input validation in firmware for some Intel® NUC may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-39539', 'title': 'AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a PNG Logo file with dangerous type by Local access. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45233', 'title': "EDK2's Network Package is susceptible to an infinite lop vulnerability when parsing a PadN option in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45234', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability when processing DNS Servers option from a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2022-36763
INTEL-SA-01022
Intel® NUC BIOS Firmware Advisory
Potential security vulnerabilities in some Intel® NUC BIOS Firmware may allow escalation of privilege, denial of service, information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities.
MEDIUM
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01022.html
b0a5ef6cdc0371c9edff9c3906798f86112a935bb6235de8954bf142b8f2dab5
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® NUC BIOS Firmware may allow escalation of privilege, denial of service, information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating the affected Intel® NUC BIOS firmware to the latest version\xa0\r\n\r\nIntel® NUC X15 Laptop Kits\r\n\r\nDownload Link\r\n\r\nLAPAC71G, LAPAC71H\r\n\r\nACADL357.0065\r\n\r\nLAPBC510, LAPBC710\r\n\r\nBCTGL357.0083\r\n\r\nLAPRC510, LAPRC710\r\n\r\nRCADL357.0066\r\n\r\nLAPKC51E, LAPKC71E, LAPKC71F\r\n\r\nKCTGL357.0048', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® NUC BIOS Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01022', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01022.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank Yngweijw\xa0 (CVE-2024-34163) for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-45229', 'title': "EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing the IA_NA or IA_TA option in a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2022-36763', 'title': 'EDK2 is susceptible to a vulnerability in the Tcg2MeasureGptTable() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45231', 'title': "EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing Neighbor Discovery Redirect message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45232', 'title': "EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45237', 'title': "EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45235', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability when handling Server ID option from a DHCPv6 proxy Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45230', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability via a long server ID option in DHCPv6 client. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45236', 'title': "EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-34163', 'title': 'Improper input validation in firmware for some Intel® NUC may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-39539', 'title': 'AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a PNG Logo file with dangerous type by Local access. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45233', 'title': "EDK2's Network Package is susceptible to an infinite lop vulnerability when parsing a PadN option in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45234', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability when processing DNS Servers option from a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2023-45231
INTEL-SA-01022
Intel® NUC BIOS Firmware Advisory
Potential security vulnerabilities in some Intel® NUC BIOS Firmware may allow escalation of privilege, denial of service, information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities.
MEDIUM
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01022.html
f601d29e9786d49e1ff98315446c3a71049eee0960937e8fa840fc9b8f8778a5
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® NUC BIOS Firmware may allow escalation of privilege, denial of service, information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating the affected Intel® NUC BIOS firmware to the latest version\xa0\r\n\r\nIntel® NUC X15 Laptop Kits\r\n\r\nDownload Link\r\n\r\nLAPAC71G, LAPAC71H\r\n\r\nACADL357.0065\r\n\r\nLAPBC510, LAPBC710\r\n\r\nBCTGL357.0083\r\n\r\nLAPRC510, LAPRC710\r\n\r\nRCADL357.0066\r\n\r\nLAPKC51E, LAPKC71E, LAPKC71F\r\n\r\nKCTGL357.0048', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® NUC BIOS Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01022', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01022.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank Yngweijw\xa0 (CVE-2024-34163) for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-45229', 'title': "EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing the IA_NA or IA_TA option in a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2022-36763', 'title': 'EDK2 is susceptible to a vulnerability in the Tcg2MeasureGptTable() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45231', 'title': "EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing Neighbor Discovery Redirect message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45232', 'title': "EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45237', 'title': "EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45235', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability when handling Server ID option from a DHCPv6 proxy Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45230', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability via a long server ID option in DHCPv6 client. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45236', 'title': "EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-34163', 'title': 'Improper input validation in firmware for some Intel® NUC may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-39539', 'title': 'AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a PNG Logo file with dangerous type by Local access. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45233', 'title': "EDK2's Network Package is susceptible to an infinite lop vulnerability when parsing a PadN option in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45234', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability when processing DNS Servers option from a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2023-45232
INTEL-SA-01022
Intel® NUC BIOS Firmware Advisory
Potential security vulnerabilities in some Intel® NUC BIOS Firmware may allow escalation of privilege, denial of service, information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities.
MEDIUM
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01022.html
1d4abf52a83f963db42d64c2013d263c23437fd2f75c44cca41988f62cc38fb7
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® NUC BIOS Firmware may allow escalation of privilege, denial of service, information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating the affected Intel® NUC BIOS firmware to the latest version\xa0\r\n\r\nIntel® NUC X15 Laptop Kits\r\n\r\nDownload Link\r\n\r\nLAPAC71G, LAPAC71H\r\n\r\nACADL357.0065\r\n\r\nLAPBC510, LAPBC710\r\n\r\nBCTGL357.0083\r\n\r\nLAPRC510, LAPRC710\r\n\r\nRCADL357.0066\r\n\r\nLAPKC51E, LAPKC71E, LAPKC71F\r\n\r\nKCTGL357.0048', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® NUC BIOS Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01022', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01022.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank Yngweijw\xa0 (CVE-2024-34163) for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-45229', 'title': "EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing the IA_NA or IA_TA option in a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2022-36763', 'title': 'EDK2 is susceptible to a vulnerability in the Tcg2MeasureGptTable() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45231', 'title': "EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing Neighbor Discovery Redirect message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45232', 'title': "EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45237', 'title': "EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45235', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability when handling Server ID option from a DHCPv6 proxy Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45230', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability via a long server ID option in DHCPv6 client. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45236', 'title': "EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-34163', 'title': 'Improper input validation in firmware for some Intel® NUC may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-39539', 'title': 'AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a PNG Logo file with dangerous type by Local access. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45233', 'title': "EDK2's Network Package is susceptible to an infinite lop vulnerability when parsing a PadN option in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45234', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability when processing DNS Servers option from a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2023-45237
INTEL-SA-01022
Intel® NUC BIOS Firmware Advisory
Potential security vulnerabilities in some Intel® NUC BIOS Firmware may allow escalation of privilege, denial of service, information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities.
MEDIUM
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01022.html
651af2c27c1b629cfc3a564e48efd99290465f66c5b540e9da8d12283f57dc9d
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® NUC BIOS Firmware may allow escalation of privilege, denial of service, information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating the affected Intel® NUC BIOS firmware to the latest version\xa0\r\n\r\nIntel® NUC X15 Laptop Kits\r\n\r\nDownload Link\r\n\r\nLAPAC71G, LAPAC71H\r\n\r\nACADL357.0065\r\n\r\nLAPBC510, LAPBC710\r\n\r\nBCTGL357.0083\r\n\r\nLAPRC510, LAPRC710\r\n\r\nRCADL357.0066\r\n\r\nLAPKC51E, LAPKC71E, LAPKC71F\r\n\r\nKCTGL357.0048', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® NUC BIOS Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01022', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01022.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank Yngweijw\xa0 (CVE-2024-34163) for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-45229', 'title': "EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing the IA_NA or IA_TA option in a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2022-36763', 'title': 'EDK2 is susceptible to a vulnerability in the Tcg2MeasureGptTable() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45231', 'title': "EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing Neighbor Discovery Redirect message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45232', 'title': "EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45237', 'title': "EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45235', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability when handling Server ID option from a DHCPv6 proxy Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45230', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability via a long server ID option in DHCPv6 client. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45236', 'title': "EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-34163', 'title': 'Improper input validation in firmware for some Intel® NUC may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-39539', 'title': 'AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a PNG Logo file with dangerous type by Local access. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45233', 'title': "EDK2's Network Package is susceptible to an infinite lop vulnerability when parsing a PadN option in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45234', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability when processing DNS Servers option from a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2023-45235
INTEL-SA-01022
Intel® NUC BIOS Firmware Advisory
Potential security vulnerabilities in some Intel® NUC BIOS Firmware may allow escalation of privilege, denial of service, information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities.
MEDIUM
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01022.html
bf5a9510e574860df0567c720cdb85dbc0851803d6a684fb0936974d7e0fa685
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® NUC BIOS Firmware may allow escalation of privilege, denial of service, information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating the affected Intel® NUC BIOS firmware to the latest version\xa0\r\n\r\nIntel® NUC X15 Laptop Kits\r\n\r\nDownload Link\r\n\r\nLAPAC71G, LAPAC71H\r\n\r\nACADL357.0065\r\n\r\nLAPBC510, LAPBC710\r\n\r\nBCTGL357.0083\r\n\r\nLAPRC510, LAPRC710\r\n\r\nRCADL357.0066\r\n\r\nLAPKC51E, LAPKC71E, LAPKC71F\r\n\r\nKCTGL357.0048', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® NUC BIOS Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01022', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01022.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank Yngweijw\xa0 (CVE-2024-34163) for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-45229', 'title': "EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing the IA_NA or IA_TA option in a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2022-36763', 'title': 'EDK2 is susceptible to a vulnerability in the Tcg2MeasureGptTable() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45231', 'title': "EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing Neighbor Discovery Redirect message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45232', 'title': "EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45237', 'title': "EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45235', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability when handling Server ID option from a DHCPv6 proxy Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45230', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability via a long server ID option in DHCPv6 client. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45236', 'title': "EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-34163', 'title': 'Improper input validation in firmware for some Intel® NUC may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-39539', 'title': 'AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a PNG Logo file with dangerous type by Local access. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45233', 'title': "EDK2's Network Package is susceptible to an infinite lop vulnerability when parsing a PadN option in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45234', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability when processing DNS Servers option from a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2023-45230
INTEL-SA-01022
Intel® NUC BIOS Firmware Advisory
Potential security vulnerabilities in some Intel® NUC BIOS Firmware may allow escalation of privilege, denial of service, information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities.
MEDIUM
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01022.html
f7156b0a42122496ff6487d5c2bd8da21ad43ecf8fe8bfa5746a83a568e3eb02
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® NUC BIOS Firmware may allow escalation of privilege, denial of service, information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating the affected Intel® NUC BIOS firmware to the latest version\xa0\r\n\r\nIntel® NUC X15 Laptop Kits\r\n\r\nDownload Link\r\n\r\nLAPAC71G, LAPAC71H\r\n\r\nACADL357.0065\r\n\r\nLAPBC510, LAPBC710\r\n\r\nBCTGL357.0083\r\n\r\nLAPRC510, LAPRC710\r\n\r\nRCADL357.0066\r\n\r\nLAPKC51E, LAPKC71E, LAPKC71F\r\n\r\nKCTGL357.0048', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® NUC BIOS Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01022', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01022.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank Yngweijw\xa0 (CVE-2024-34163) for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-45229', 'title': "EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing the IA_NA or IA_TA option in a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2022-36763', 'title': 'EDK2 is susceptible to a vulnerability in the Tcg2MeasureGptTable() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45231', 'title': "EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing Neighbor Discovery Redirect message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45232', 'title': "EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45237', 'title': "EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45235', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability when handling Server ID option from a DHCPv6 proxy Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45230', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability via a long server ID option in DHCPv6 client. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45236', 'title': "EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-34163', 'title': 'Improper input validation in firmware for some Intel® NUC may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-39539', 'title': 'AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a PNG Logo file with dangerous type by Local access. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45233', 'title': "EDK2's Network Package is susceptible to an infinite lop vulnerability when parsing a PadN option in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45234', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability when processing DNS Servers option from a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2023-45236
INTEL-SA-01022
Intel® NUC BIOS Firmware Advisory
Potential security vulnerabilities in some Intel® NUC BIOS Firmware may allow escalation of privilege, denial of service, information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities.
MEDIUM
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01022.html
a46b01dbdaace6dcf77130c3ecd96d88a326624891e52de9e945c117c9cb40e1
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® NUC BIOS Firmware may allow escalation of privilege, denial of service, information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating the affected Intel® NUC BIOS firmware to the latest version\xa0\r\n\r\nIntel® NUC X15 Laptop Kits\r\n\r\nDownload Link\r\n\r\nLAPAC71G, LAPAC71H\r\n\r\nACADL357.0065\r\n\r\nLAPBC510, LAPBC710\r\n\r\nBCTGL357.0083\r\n\r\nLAPRC510, LAPRC710\r\n\r\nRCADL357.0066\r\n\r\nLAPKC51E, LAPKC71E, LAPKC71F\r\n\r\nKCTGL357.0048', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® NUC BIOS Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01022', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01022.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank Yngweijw\xa0 (CVE-2024-34163) for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-45229', 'title': "EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing the IA_NA or IA_TA option in a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2022-36763', 'title': 'EDK2 is susceptible to a vulnerability in the Tcg2MeasureGptTable() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45231', 'title': "EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing Neighbor Discovery Redirect message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45232', 'title': "EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45237', 'title': "EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45235', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability when handling Server ID option from a DHCPv6 proxy Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45230', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability via a long server ID option in DHCPv6 client. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45236', 'title': "EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-34163', 'title': 'Improper input validation in firmware for some Intel® NUC may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-39539', 'title': 'AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a PNG Logo file with dangerous type by Local access. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45233', 'title': "EDK2's Network Package is susceptible to an infinite lop vulnerability when parsing a PadN option in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45234', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability when processing DNS Servers option from a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-34163
INTEL-SA-01022
Intel® NUC BIOS Firmware Advisory
Potential security vulnerabilities in some Intel® NUC BIOS Firmware may allow escalation of privilege, denial of service, information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities.
MEDIUM
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01022.html
35d3b0088dc2f4d77351eb738906eae89852eeb26ff52b995be6f3a576cf2b71
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® NUC BIOS Firmware may allow escalation of privilege, denial of service, information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating the affected Intel® NUC BIOS firmware to the latest version\xa0\r\n\r\nIntel® NUC X15 Laptop Kits\r\n\r\nDownload Link\r\n\r\nLAPAC71G, LAPAC71H\r\n\r\nACADL357.0065\r\n\r\nLAPBC510, LAPBC710\r\n\r\nBCTGL357.0083\r\n\r\nLAPRC510, LAPRC710\r\n\r\nRCADL357.0066\r\n\r\nLAPKC51E, LAPKC71E, LAPKC71F\r\n\r\nKCTGL357.0048', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® NUC BIOS Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01022', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01022.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank Yngweijw\xa0 (CVE-2024-34163) for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-45229', 'title': "EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing the IA_NA or IA_TA option in a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2022-36763', 'title': 'EDK2 is susceptible to a vulnerability in the Tcg2MeasureGptTable() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45231', 'title': "EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing Neighbor Discovery Redirect message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45232', 'title': "EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45237', 'title': "EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45235', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability when handling Server ID option from a DHCPv6 proxy Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45230', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability via a long server ID option in DHCPv6 client. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45236', 'title': "EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-34163', 'title': 'Improper input validation in firmware for some Intel® NUC may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-39539', 'title': 'AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a PNG Logo file with dangerous type by Local access. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45233', 'title': "EDK2's Network Package is susceptible to an infinite lop vulnerability when parsing a PadN option in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45234', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability when processing DNS Servers option from a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2023-39539
INTEL-SA-01022
Intel® NUC BIOS Firmware Advisory
Potential security vulnerabilities in some Intel® NUC BIOS Firmware may allow escalation of privilege, denial of service, information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities.
MEDIUM
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01022.html
cc256e9b365ae787f4a2bde96981af91669ae79500f676412e816deddd2b77dd
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® NUC BIOS Firmware may allow escalation of privilege, denial of service, information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating the affected Intel® NUC BIOS firmware to the latest version\xa0\r\n\r\nIntel® NUC X15 Laptop Kits\r\n\r\nDownload Link\r\n\r\nLAPAC71G, LAPAC71H\r\n\r\nACADL357.0065\r\n\r\nLAPBC510, LAPBC710\r\n\r\nBCTGL357.0083\r\n\r\nLAPRC510, LAPRC710\r\n\r\nRCADL357.0066\r\n\r\nLAPKC51E, LAPKC71E, LAPKC71F\r\n\r\nKCTGL357.0048', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® NUC BIOS Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01022', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01022.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank Yngweijw\xa0 (CVE-2024-34163) for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-45229', 'title': "EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing the IA_NA or IA_TA option in a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2022-36763', 'title': 'EDK2 is susceptible to a vulnerability in the Tcg2MeasureGptTable() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45231', 'title': "EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing Neighbor Discovery Redirect message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45232', 'title': "EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45237', 'title': "EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45235', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability when handling Server ID option from a DHCPv6 proxy Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45230', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability via a long server ID option in DHCPv6 client. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45236', 'title': "EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-34163', 'title': 'Improper input validation in firmware for some Intel® NUC may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-39539', 'title': 'AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a PNG Logo file with dangerous type by Local access. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45233', 'title': "EDK2's Network Package is susceptible to an infinite lop vulnerability when parsing a PadN option in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45234', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability when processing DNS Servers option from a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2023-45233
INTEL-SA-01022
Intel® NUC BIOS Firmware Advisory
Potential security vulnerabilities in some Intel® NUC BIOS Firmware may allow escalation of privilege, denial of service, information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities.
MEDIUM
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01022.html
b0770d10cb2cb2628c204eb27b9f5c5564d45cb2989ef61ea98cbb24c72814eb
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® NUC BIOS Firmware may allow escalation of privilege, denial of service, information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating the affected Intel® NUC BIOS firmware to the latest version\xa0\r\n\r\nIntel® NUC X15 Laptop Kits\r\n\r\nDownload Link\r\n\r\nLAPAC71G, LAPAC71H\r\n\r\nACADL357.0065\r\n\r\nLAPBC510, LAPBC710\r\n\r\nBCTGL357.0083\r\n\r\nLAPRC510, LAPRC710\r\n\r\nRCADL357.0066\r\n\r\nLAPKC51E, LAPKC71E, LAPKC71F\r\n\r\nKCTGL357.0048', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® NUC BIOS Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01022', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01022.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank Yngweijw\xa0 (CVE-2024-34163) for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-45229', 'title': "EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing the IA_NA or IA_TA option in a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2022-36763', 'title': 'EDK2 is susceptible to a vulnerability in the Tcg2MeasureGptTable() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45231', 'title': "EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing Neighbor Discovery Redirect message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45232', 'title': "EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45237', 'title': "EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45235', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability when handling Server ID option from a DHCPv6 proxy Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45230', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability via a long server ID option in DHCPv6 client. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45236', 'title': "EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-34163', 'title': 'Improper input validation in firmware for some Intel® NUC may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-39539', 'title': 'AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a PNG Logo file with dangerous type by Local access. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45233', 'title': "EDK2's Network Package is susceptible to an infinite lop vulnerability when parsing a PadN option in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45234', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability when processing DNS Servers option from a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2023-45234
INTEL-SA-01022
Intel® NUC BIOS Firmware Advisory
Potential security vulnerabilities in some Intel® NUC BIOS Firmware may allow escalation of privilege, denial of service, information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities.
MEDIUM
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01022.html
35b001f3ef7dcc3847d8ba7ed2c0f133e5c93c8896ffc41e210fa7379afb4cec
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® NUC BIOS Firmware may allow escalation of privilege, denial of service, information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating the affected Intel® NUC BIOS firmware to the latest version\xa0\r\n\r\nIntel® NUC X15 Laptop Kits\r\n\r\nDownload Link\r\n\r\nLAPAC71G, LAPAC71H\r\n\r\nACADL357.0065\r\n\r\nLAPBC510, LAPBC710\r\n\r\nBCTGL357.0083\r\n\r\nLAPRC510, LAPRC710\r\n\r\nRCADL357.0066\r\n\r\nLAPKC51E, LAPKC71E, LAPKC71F\r\n\r\nKCTGL357.0048', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® NUC BIOS Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01022', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01022.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank Yngweijw\xa0 (CVE-2024-34163) for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-45229', 'title': "EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing the IA_NA or IA_TA option in a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2022-36763', 'title': 'EDK2 is susceptible to a vulnerability in the Tcg2MeasureGptTable() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45231', 'title': "EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing Neighbor Discovery Redirect message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45232', 'title': "EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45237', 'title': "EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45235', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability when handling Server ID option from a DHCPv6 proxy Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45230', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability via a long server ID option in DHCPv6 client. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45236', 'title': "EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-34163', 'title': 'Improper input validation in firmware for some Intel® NUC may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-39539', 'title': 'AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a PNG Logo file with dangerous type by Local access. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45233', 'title': "EDK2's Network Package is susceptible to an infinite lop vulnerability when parsing a PadN option in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45234', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability when processing DNS Servers option from a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-29076
INTEL-SA-01024
Intel® CST Software Advisory
A potential security vulnerability in some Intel® Context Sensing Technology (Intel® CST) software may allow denial of service. Intel is releasing software updates to mitigate these potential vulnerabilities.
MEDIUM
2024-11-12 03:00:00+03:00
2024-11-12 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01024.html
d8c6f15c8a5b3163530c62433f54336b0f4d0924d32fb5080c8d7b265266d798
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® Context Sensing Technology (Intel® CST) software may allow denial of service. Intel is releasing software updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of Intel® CST software update to the latest version provided by the system manufacturer that addresses this issue.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Denial of Service', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® CST Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01024', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-11-12T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-11-12T00:00:00+00:00', 'initial_release_date': '2024-11-12T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01024.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Copyright © Intel Corporation All rights reserved.'}, 'acknowledgments': [{'names': ['This issue was found internally. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-29076', 'cwe': {'id': 'CWE-248', 'name': 'Uncaught Exception'}, 'title': 'Uncaught exception for some Intel® CST software before version 8.7.10803 may allow an authenticated user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.5, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.8, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'NONE', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'HIGH', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'NONE'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-39805
INTEL-SA-01030
Intel® Driver Support Assistant Software Advisory
A potential security vulnerability in some Intel® Driver Support Assistant (Intel® DSA) software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.
HIGH
2025-02-11 03:00:00+03:00
2025-02-11 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01030.html
c9d0d30696a061c847e592afcf53e847215a781a1ca94395af3c30b693bf59a2
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® Driver Support Assistant (Intel® DSA) software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating Intel® DSA software to version 23.4.39 or later.Updates are available for download at this location:https://www.intel.com/content/www/us/en/support/intel-driver-support-assistant.html', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': ' Intel® Driver Support Assistant Software Advisory ', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01030', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2025-02-11T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2025-02-11T00:00:00+00:00', 'initial_release_date': '2025-02-11T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01030.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Copyright © Intel Corporation All rights reserved.'}, 'acknowledgments': [{'names': ['Intel would like to thank @sim0nsecurity for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-39805', 'cwe': {'id': 'CWE-345', 'name': 'Insufficient Verification of Data Authenticity'}, 'title': 'Insufficient verification of data authenticity in some Intel® DSA software before version 23.4.39 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7.3, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'HIGH', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2023-42667
INTEL-SA-01038
Intel® Core™ Ultra Processor Stream Cache Advisory
A potential security vulnerability in the Intel® Core™ Ultra Processor stream cache mechanism may allow escalation of privilege. Intel is releasing microcode updates to mitigate this potential vulnerability.
HIGH
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01038.html
0589e377c5a018126a5b040ebc29d2e9789eff84bccf8df35ddb159fac3ba5a8
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in the Intel® Core™ Ultra Processor stream cache mechanism may allow escalation of privilege. Intel is releasing microcode updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of affected Intel® Processors update to the latest version firmware provided by the system manufacturer that addresses these issues.\r\nIntel has released microcode version 0x17 for the affected Intel® Core™ Ultra processors that are currently supported on the public github repository.\r\nPlease see details below on access to the microcode:Public Github: https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files.\r\nThe microcode patch can be OS loaded.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Hardware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Core™ Ultra Processor Stream Cache Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01038', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01038.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['This issue was discovered internally by Intel employees. Intel would like to thanks Rober J Miller, Brent Calhoon, Priel Aharonian, Persio Morrobel Gomez and Paul Grosen for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-42667', 'title': 'Improper isolation in the Intel® Core™ Ultra Processor stream cache mechanism may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-21830
INTEL-SA-01044
Intel® VPL Software Advisory
A potential security vulnerability in some Intel® Video Processing Library (VPL) software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.
MEDIUM
2025-02-11 03:00:00+03:00
2025-02-11 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01044.html
d80c8b1be7c0e2f704ee68e0323fdf725d28bac034ea403eda304748b705b55d
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® Video Processing Library (VPL) software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating Intel® 7th-10th Gen Processor graphics for Windows to version 31.0.101.2130 or later.Updates are available for download at this location: \xa0https://www.intel.com/content/www/us/en/download/776137\xa0Intel recommends updating Intel® Arc™ & Iris® Xe graphics for Windows to version 31.0.101.5186_101.5234 or later.Updates are available for download at this location: \xa0https://www.intel.com/content/www/us/en/download/785597\xa0Intel recommends updating Intel® Arc™ Pro graphics for Windows to version 31.0.101.5319 or later.Updates are available for download at this location: \xa0https://www.intel.com/content/www/us/en/download/741626\xa0Intel recommends updating Intel® Data Center GPU Flex Series for Windows to version 31.0.101.5333 or later.Updates are available for download at this location: \xa0https://www.intel.com/content/www/us/en/download/780185\xa0Intel recommends updating Intel® VPL software to version 2023.4.0 or later.Updates are available for download at this location: \xa0https://github.com/intel/libvpl/releases', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® VPL Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01044', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2025-02-11T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2025-02-11T00:00:00+00:00', 'initial_release_date': '2025-02-11T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01044.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Copyright © Intel Corporation All rights reserved.'}, 'acknowledgments': [{'names': ['Intel would like to thank ycdxsb for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-21830', 'cwe': {'id': 'CWE-427', 'name': 'Uncontrolled Search Path Element'}, 'title': 'Uncontrolled search path in some Intel® VPL software before version 2023.4.0 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.7, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'HIGH', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'userInteraction': 'ACTIVE', 'attackComplexity': 'HIGH', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'HIGH', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2023-49141
INTEL-SA-01046
2024.2 IPU - Intel® Processor Stream Cache Advisory
A potential security vulnerability in some Intel® Processor stream cache mechanisms may allow escalation of privilege. Intel is releasing microcode updates to mitigate this potential vulnerability.
HIGH
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01046.html
fbc19178d4d01b5adc3facd1e8be8644c3e3b6debbd4d6d4fcb8f32a49a7ac54
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® Processor stream cache mechanisms may allow escalation of privilege. Intel is releasing microcode updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of affected Intel® Processors update to the latest version firmware provided by the system manufacturer that addresses these issues.\r\nIntel has released microcode update for the affected products that are currently supported on the public github repository.\r\nPlease see details below on access to the microcode:Public Github: \xa0https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files.\r\nThe microcode patch can be OS loaded.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Hardware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': '2024.2 IPU - Intel® Processor Stream Cache Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01046', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01046.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['This issue was discovered internally by Intel employees. Intel would like to thanks Rober J Miller, Brent Calhoon, Priel Aharonian, Persio Morrobel Gomez and Paul Grosen for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-49141', 'title': 'Improper isolation in some Intel® Processors stream cache mechanism may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-21857
INTEL-SA-01057
Intel® oneAPI Compiler Software Advisory
A potential security vulnerability in some Intel® oneAPI Compiler software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.
MEDIUM
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01057.html
f9b5d8577e7fe8aa5dcae77d76ceacf77b18305c50b270bb54576014503fa6f8
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® oneAPI Compiler software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating Intel® oneAPI DPC++/C++ Compiler to version 2024.1 or later.\r\nUpdates are available for download at this location:\r\nhttps://www.intel.com/content/www/us/en/developer/articles/tool/oneapi-standalone-components.html#dpcpp-cpp\r\n\xa0\r\nIntel recommends updating Intel® Fortran Compiler to version 2024.1 or later.\r\nUpdates are available for download at this location:\r\nhttps://www.intel.com/content/www/us/en/developer/articles/tool/oneapi-standalone-components.html#fortran\r\n\xa0\r\nIntel recommends updating Intel® oneAPI Base Toolkit to version 2024.1 or later.\r\nUpdates are available for download at this location:\r\nhttps://www.intel.com/content/www/us/en/developer/tools/oneapi/base-toolkit-download.html\r\n\xa0\r\nIntel recommends updating Intel® oneAPI HPC Toolkit to version 2024.1 or later.\r\nUpdates are available for download at this location:\r\nhttps://www.intel.com/content/www/us/en/developer/tools/oneapi/hpc-toolkit.html#gs.36knya\r\n\xa0\r\nIntel recommends updating Intel® Distribution for Python for Windows to version 2024.1 or later.\r\nUpdates are available for download at this location:\r\nhttps://www.intel.com/content/www/us/en/developer/tools/oneapi/distribution-for-python.html#gs.3slms1', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® oneAPI Compiler Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01057', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01057.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank ycdxsb for reporting this issue as well as Intel employee William Huhn. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-21857', 'title': 'Uncontrolled search path for some Intel® oneAPI Compiler software before version 2024.1 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-21801
INTEL-SA-01070
Intel® TDX Module Software Advisory
Potential security vulnerabily in some Intel® Trust Domain Extensions (Intel® TDX) module software may allow denial of service. Intel is releasing firmware updates to mitigate these potential vulnerabilities.
HIGH
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01070.html
6b6cd539c4d877d5d63e16db906ec3c31cacc4026d601c3f3619c4b8a608c919
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabily in some Intel® Trust Domain Extensions (Intel® TDX) module software may allow denial of service. Intel is releasing firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of the Intel® TDX module update to the latest version provided by the system manufacturer that addresses these issues.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Hardware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Denial of Service', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® TDX Module Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01070', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01070.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['This issue was found internally by Intel. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-21801', 'title': 'Insufficient control flow management in some Intel® TDX module software before version 1.5.05.46.698 may allow a privileged user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.1, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2023-23904
INTEL-SA-01071
2024.3 IPU - UEFI Firmware Advisory
Potential security vulnerabilities in UEFI firmware for some Intel® Processors may allow escalation of privilege, denial of service or information disclosure. Intel is releasing UEFI firmware updates to mitigate these potential vulnerabilities.
MEDIUM
2024-09-10 03:00:00+03:00
2024-09-10 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01071.html
9a1e1dafb8a1757adeeb945683527b4283b2030c6111d8ea8317ccf234a87865
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in UEFI firmware for some Intel® Processors may allow escalation of privilege, denial of service or information disclosure. Intel is releasing UEFI firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of Intel® Processors update to the latest version provided by the system manufacturer that addresses these issues.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': '2024.3 IPU - UEFI Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01071', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-09-10T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-09-10T00:00:00+00:00', 'initial_release_date': '2024-09-10T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01071.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['The following were found by Intel employees.\xa0 Intel would like to thank Ilya Alexandrovich (CVE-2023-43753) and Majid Shushtarian, Richard Thomaiyar, James Mihm, Vernon Maurey, Nilanthren (CVE-2024-23599).\r\nIntel would like to thank Phoenix Technologies (CVE-2023-43626), Yngweijw (CVE-2024-21871, CVE-2023-42772, CVE-2023-41833, CVE-2024-21829), Jeremy Boone (@uffeux) (CVE-2023-22351, CVE-2023-23904, CVE-2023-25546) for reporting these issues. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-23904', 'title': 'NULL pointer dereference in the UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-43626', 'title': 'Improper access control in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21781', 'title': 'Improper input validation in UEFI firmware for some Intel® Processors may allow a privileged user to enable information disclosure or denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:H/SC:H/SI:N/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23599', 'title': 'Race condition in Seamless Firmware Updates for some Intel® reference platforms may allow a privileged user to potentially enable denial of service via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.9, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21829', 'title': 'Improper input validation in UEFI firmware error handler for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-25546', 'title': 'Out-of-bounds read in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 2.5, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 1.8, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-43753', 'title': 'Improper conditions check in some Intel(R) Processors with Intel® Software Guard Extensions (Intel® SGX) may allow a privileged user to potentially enable information disclosure via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-42772', 'title': 'Untrusted pointer dereference in UEFI firmware for some Intel® reference processors may allow a privileged user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21871', 'title': 'Improper input validation in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-22351', 'title': 'Out-of-bounds write in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-41833', 'title': 'A race condition in UEFI firmware for some Intel® processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2023-43626
INTEL-SA-01071
2024.3 IPU - UEFI Firmware Advisory
Potential security vulnerabilities in UEFI firmware for some Intel® Processors may allow escalation of privilege, denial of service or information disclosure. Intel is releasing UEFI firmware updates to mitigate these potential vulnerabilities.
MEDIUM
2024-09-10 03:00:00+03:00
2024-09-10 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01071.html
408ecf7ac24bba92924c19656cf9bd9aa5ec2cc71ad64110a7fa40a82edb0169
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in UEFI firmware for some Intel® Processors may allow escalation of privilege, denial of service or information disclosure. Intel is releasing UEFI firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of Intel® Processors update to the latest version provided by the system manufacturer that addresses these issues.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': '2024.3 IPU - UEFI Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01071', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-09-10T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-09-10T00:00:00+00:00', 'initial_release_date': '2024-09-10T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01071.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['The following were found by Intel employees.\xa0 Intel would like to thank Ilya Alexandrovich (CVE-2023-43753) and Majid Shushtarian, Richard Thomaiyar, James Mihm, Vernon Maurey, Nilanthren (CVE-2024-23599).\r\nIntel would like to thank Phoenix Technologies (CVE-2023-43626), Yngweijw (CVE-2024-21871, CVE-2023-42772, CVE-2023-41833, CVE-2024-21829), Jeremy Boone (@uffeux) (CVE-2023-22351, CVE-2023-23904, CVE-2023-25546) for reporting these issues. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-23904', 'title': 'NULL pointer dereference in the UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-43626', 'title': 'Improper access control in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21781', 'title': 'Improper input validation in UEFI firmware for some Intel® Processors may allow a privileged user to enable information disclosure or denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:H/SC:H/SI:N/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23599', 'title': 'Race condition in Seamless Firmware Updates for some Intel® reference platforms may allow a privileged user to potentially enable denial of service via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.9, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21829', 'title': 'Improper input validation in UEFI firmware error handler for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-25546', 'title': 'Out-of-bounds read in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 2.5, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 1.8, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-43753', 'title': 'Improper conditions check in some Intel(R) Processors with Intel® Software Guard Extensions (Intel® SGX) may allow a privileged user to potentially enable information disclosure via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-42772', 'title': 'Untrusted pointer dereference in UEFI firmware for some Intel® reference processors may allow a privileged user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21871', 'title': 'Improper input validation in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-22351', 'title': 'Out-of-bounds write in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-41833', 'title': 'A race condition in UEFI firmware for some Intel® processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-21781
INTEL-SA-01071
2024.3 IPU - UEFI Firmware Advisory
Potential security vulnerabilities in UEFI firmware for some Intel® Processors may allow escalation of privilege, denial of service or information disclosure. Intel is releasing UEFI firmware updates to mitigate these potential vulnerabilities.
MEDIUM
2024-09-10 03:00:00+03:00
2024-09-10 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01071.html
60573c84a094988bf70cf49fd3b8a63e04a062778b6f521036cd71387884005c
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in UEFI firmware for some Intel® Processors may allow escalation of privilege, denial of service or information disclosure. Intel is releasing UEFI firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of Intel® Processors update to the latest version provided by the system manufacturer that addresses these issues.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': '2024.3 IPU - UEFI Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01071', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-09-10T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-09-10T00:00:00+00:00', 'initial_release_date': '2024-09-10T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01071.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['The following were found by Intel employees.\xa0 Intel would like to thank Ilya Alexandrovich (CVE-2023-43753) and Majid Shushtarian, Richard Thomaiyar, James Mihm, Vernon Maurey, Nilanthren (CVE-2024-23599).\r\nIntel would like to thank Phoenix Technologies (CVE-2023-43626), Yngweijw (CVE-2024-21871, CVE-2023-42772, CVE-2023-41833, CVE-2024-21829), Jeremy Boone (@uffeux) (CVE-2023-22351, CVE-2023-23904, CVE-2023-25546) for reporting these issues. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-23904', 'title': 'NULL pointer dereference in the UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-43626', 'title': 'Improper access control in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21781', 'title': 'Improper input validation in UEFI firmware for some Intel® Processors may allow a privileged user to enable information disclosure or denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:H/SC:H/SI:N/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23599', 'title': 'Race condition in Seamless Firmware Updates for some Intel® reference platforms may allow a privileged user to potentially enable denial of service via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.9, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21829', 'title': 'Improper input validation in UEFI firmware error handler for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-25546', 'title': 'Out-of-bounds read in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 2.5, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 1.8, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-43753', 'title': 'Improper conditions check in some Intel(R) Processors with Intel® Software Guard Extensions (Intel® SGX) may allow a privileged user to potentially enable information disclosure via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-42772', 'title': 'Untrusted pointer dereference in UEFI firmware for some Intel® reference processors may allow a privileged user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21871', 'title': 'Improper input validation in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-22351', 'title': 'Out-of-bounds write in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-41833', 'title': 'A race condition in UEFI firmware for some Intel® processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-23599
INTEL-SA-01071
2024.3 IPU - UEFI Firmware Advisory
Potential security vulnerabilities in UEFI firmware for some Intel® Processors may allow escalation of privilege, denial of service or information disclosure. Intel is releasing UEFI firmware updates to mitigate these potential vulnerabilities.
MEDIUM
2024-09-10 03:00:00+03:00
2024-09-10 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01071.html
b6917e1226da47353e2cdf9f6b4003eabad41486a751d51f4c3beaa92bb03366
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in UEFI firmware for some Intel® Processors may allow escalation of privilege, denial of service or information disclosure. Intel is releasing UEFI firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of Intel® Processors update to the latest version provided by the system manufacturer that addresses these issues.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': '2024.3 IPU - UEFI Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01071', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-09-10T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-09-10T00:00:00+00:00', 'initial_release_date': '2024-09-10T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01071.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['The following were found by Intel employees.\xa0 Intel would like to thank Ilya Alexandrovich (CVE-2023-43753) and Majid Shushtarian, Richard Thomaiyar, James Mihm, Vernon Maurey, Nilanthren (CVE-2024-23599).\r\nIntel would like to thank Phoenix Technologies (CVE-2023-43626), Yngweijw (CVE-2024-21871, CVE-2023-42772, CVE-2023-41833, CVE-2024-21829), Jeremy Boone (@uffeux) (CVE-2023-22351, CVE-2023-23904, CVE-2023-25546) for reporting these issues. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-23904', 'title': 'NULL pointer dereference in the UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-43626', 'title': 'Improper access control in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21781', 'title': 'Improper input validation in UEFI firmware for some Intel® Processors may allow a privileged user to enable information disclosure or denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:H/SC:H/SI:N/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23599', 'title': 'Race condition in Seamless Firmware Updates for some Intel® reference platforms may allow a privileged user to potentially enable denial of service via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.9, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21829', 'title': 'Improper input validation in UEFI firmware error handler for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-25546', 'title': 'Out-of-bounds read in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 2.5, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 1.8, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-43753', 'title': 'Improper conditions check in some Intel(R) Processors with Intel® Software Guard Extensions (Intel® SGX) may allow a privileged user to potentially enable information disclosure via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-42772', 'title': 'Untrusted pointer dereference in UEFI firmware for some Intel® reference processors may allow a privileged user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21871', 'title': 'Improper input validation in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-22351', 'title': 'Out-of-bounds write in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-41833', 'title': 'A race condition in UEFI firmware for some Intel® processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-21829
INTEL-SA-01071
2024.3 IPU - UEFI Firmware Advisory
Potential security vulnerabilities in UEFI firmware for some Intel® Processors may allow escalation of privilege, denial of service or information disclosure. Intel is releasing UEFI firmware updates to mitigate these potential vulnerabilities.
MEDIUM
2024-09-10 03:00:00+03:00
2024-09-10 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01071.html
4cdf9b8e38d45d402b99793747939ebdf81575f624c2cf9237ff9f6ece2b1ea0
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in UEFI firmware for some Intel® Processors may allow escalation of privilege, denial of service or information disclosure. Intel is releasing UEFI firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of Intel® Processors update to the latest version provided by the system manufacturer that addresses these issues.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': '2024.3 IPU - UEFI Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01071', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-09-10T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-09-10T00:00:00+00:00', 'initial_release_date': '2024-09-10T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01071.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['The following were found by Intel employees.\xa0 Intel would like to thank Ilya Alexandrovich (CVE-2023-43753) and Majid Shushtarian, Richard Thomaiyar, James Mihm, Vernon Maurey, Nilanthren (CVE-2024-23599).\r\nIntel would like to thank Phoenix Technologies (CVE-2023-43626), Yngweijw (CVE-2024-21871, CVE-2023-42772, CVE-2023-41833, CVE-2024-21829), Jeremy Boone (@uffeux) (CVE-2023-22351, CVE-2023-23904, CVE-2023-25546) for reporting these issues. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-23904', 'title': 'NULL pointer dereference in the UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-43626', 'title': 'Improper access control in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21781', 'title': 'Improper input validation in UEFI firmware for some Intel® Processors may allow a privileged user to enable information disclosure or denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:H/SC:H/SI:N/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23599', 'title': 'Race condition in Seamless Firmware Updates for some Intel® reference platforms may allow a privileged user to potentially enable denial of service via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.9, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21829', 'title': 'Improper input validation in UEFI firmware error handler for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-25546', 'title': 'Out-of-bounds read in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 2.5, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 1.8, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-43753', 'title': 'Improper conditions check in some Intel(R) Processors with Intel® Software Guard Extensions (Intel® SGX) may allow a privileged user to potentially enable information disclosure via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-42772', 'title': 'Untrusted pointer dereference in UEFI firmware for some Intel® reference processors may allow a privileged user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21871', 'title': 'Improper input validation in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-22351', 'title': 'Out-of-bounds write in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-41833', 'title': 'A race condition in UEFI firmware for some Intel® processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2023-25546
INTEL-SA-01071
2024.3 IPU - UEFI Firmware Advisory
Potential security vulnerabilities in UEFI firmware for some Intel® Processors may allow escalation of privilege, denial of service or information disclosure. Intel is releasing UEFI firmware updates to mitigate these potential vulnerabilities.
MEDIUM
2024-09-10 03:00:00+03:00
2024-09-10 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01071.html
7162b9e3f51a28724f51ccafac990b6f75205a507771fa55d7d2abf11d9b7e29
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in UEFI firmware for some Intel® Processors may allow escalation of privilege, denial of service or information disclosure. Intel is releasing UEFI firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of Intel® Processors update to the latest version provided by the system manufacturer that addresses these issues.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': '2024.3 IPU - UEFI Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01071', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-09-10T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-09-10T00:00:00+00:00', 'initial_release_date': '2024-09-10T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01071.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['The following were found by Intel employees.\xa0 Intel would like to thank Ilya Alexandrovich (CVE-2023-43753) and Majid Shushtarian, Richard Thomaiyar, James Mihm, Vernon Maurey, Nilanthren (CVE-2024-23599).\r\nIntel would like to thank Phoenix Technologies (CVE-2023-43626), Yngweijw (CVE-2024-21871, CVE-2023-42772, CVE-2023-41833, CVE-2024-21829), Jeremy Boone (@uffeux) (CVE-2023-22351, CVE-2023-23904, CVE-2023-25546) for reporting these issues. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-23904', 'title': 'NULL pointer dereference in the UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-43626', 'title': 'Improper access control in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21781', 'title': 'Improper input validation in UEFI firmware for some Intel® Processors may allow a privileged user to enable information disclosure or denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:H/SC:H/SI:N/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23599', 'title': 'Race condition in Seamless Firmware Updates for some Intel® reference platforms may allow a privileged user to potentially enable denial of service via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.9, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21829', 'title': 'Improper input validation in UEFI firmware error handler for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-25546', 'title': 'Out-of-bounds read in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 2.5, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 1.8, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-43753', 'title': 'Improper conditions check in some Intel(R) Processors with Intel® Software Guard Extensions (Intel® SGX) may allow a privileged user to potentially enable information disclosure via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-42772', 'title': 'Untrusted pointer dereference in UEFI firmware for some Intel® reference processors may allow a privileged user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21871', 'title': 'Improper input validation in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-22351', 'title': 'Out-of-bounds write in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-41833', 'title': 'A race condition in UEFI firmware for some Intel® processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2023-43753
INTEL-SA-01071
2024.3 IPU - UEFI Firmware Advisory
Potential security vulnerabilities in UEFI firmware for some Intel® Processors may allow escalation of privilege, denial of service or information disclosure. Intel is releasing UEFI firmware updates to mitigate these potential vulnerabilities.
MEDIUM
2024-09-10 03:00:00+03:00
2024-09-10 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01071.html
056be2e01279e53985e0d9d00e9ea13f1d41ebbba2910d787531cbcb00b6be4f
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in UEFI firmware for some Intel® Processors may allow escalation of privilege, denial of service or information disclosure. Intel is releasing UEFI firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of Intel® Processors update to the latest version provided by the system manufacturer that addresses these issues.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': '2024.3 IPU - UEFI Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01071', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-09-10T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-09-10T00:00:00+00:00', 'initial_release_date': '2024-09-10T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01071.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['The following were found by Intel employees.\xa0 Intel would like to thank Ilya Alexandrovich (CVE-2023-43753) and Majid Shushtarian, Richard Thomaiyar, James Mihm, Vernon Maurey, Nilanthren (CVE-2024-23599).\r\nIntel would like to thank Phoenix Technologies (CVE-2023-43626), Yngweijw (CVE-2024-21871, CVE-2023-42772, CVE-2023-41833, CVE-2024-21829), Jeremy Boone (@uffeux) (CVE-2023-22351, CVE-2023-23904, CVE-2023-25546) for reporting these issues. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-23904', 'title': 'NULL pointer dereference in the UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-43626', 'title': 'Improper access control in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21781', 'title': 'Improper input validation in UEFI firmware for some Intel® Processors may allow a privileged user to enable information disclosure or denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:H/SC:H/SI:N/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23599', 'title': 'Race condition in Seamless Firmware Updates for some Intel® reference platforms may allow a privileged user to potentially enable denial of service via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.9, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21829', 'title': 'Improper input validation in UEFI firmware error handler for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-25546', 'title': 'Out-of-bounds read in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 2.5, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 1.8, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-43753', 'title': 'Improper conditions check in some Intel(R) Processors with Intel® Software Guard Extensions (Intel® SGX) may allow a privileged user to potentially enable information disclosure via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-42772', 'title': 'Untrusted pointer dereference in UEFI firmware for some Intel® reference processors may allow a privileged user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21871', 'title': 'Improper input validation in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-22351', 'title': 'Out-of-bounds write in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-41833', 'title': 'A race condition in UEFI firmware for some Intel® processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2023-42772
INTEL-SA-01071
2024.3 IPU - UEFI Firmware Advisory
Potential security vulnerabilities in UEFI firmware for some Intel® Processors may allow escalation of privilege, denial of service or information disclosure. Intel is releasing UEFI firmware updates to mitigate these potential vulnerabilities.
MEDIUM
2024-09-10 03:00:00+03:00
2024-09-10 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01071.html
fca6103c1707ad7983db6d6531ec5156732048bceb75395c9f71dd23a08c3fc4
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in UEFI firmware for some Intel® Processors may allow escalation of privilege, denial of service or information disclosure. Intel is releasing UEFI firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of Intel® Processors update to the latest version provided by the system manufacturer that addresses these issues.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': '2024.3 IPU - UEFI Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01071', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-09-10T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-09-10T00:00:00+00:00', 'initial_release_date': '2024-09-10T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01071.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['The following were found by Intel employees.\xa0 Intel would like to thank Ilya Alexandrovich (CVE-2023-43753) and Majid Shushtarian, Richard Thomaiyar, James Mihm, Vernon Maurey, Nilanthren (CVE-2024-23599).\r\nIntel would like to thank Phoenix Technologies (CVE-2023-43626), Yngweijw (CVE-2024-21871, CVE-2023-42772, CVE-2023-41833, CVE-2024-21829), Jeremy Boone (@uffeux) (CVE-2023-22351, CVE-2023-23904, CVE-2023-25546) for reporting these issues. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-23904', 'title': 'NULL pointer dereference in the UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-43626', 'title': 'Improper access control in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21781', 'title': 'Improper input validation in UEFI firmware for some Intel® Processors may allow a privileged user to enable information disclosure or denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:H/SC:H/SI:N/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23599', 'title': 'Race condition in Seamless Firmware Updates for some Intel® reference platforms may allow a privileged user to potentially enable denial of service via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.9, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21829', 'title': 'Improper input validation in UEFI firmware error handler for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-25546', 'title': 'Out-of-bounds read in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 2.5, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 1.8, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-43753', 'title': 'Improper conditions check in some Intel(R) Processors with Intel® Software Guard Extensions (Intel® SGX) may allow a privileged user to potentially enable information disclosure via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-42772', 'title': 'Untrusted pointer dereference in UEFI firmware for some Intel® reference processors may allow a privileged user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21871', 'title': 'Improper input validation in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-22351', 'title': 'Out-of-bounds write in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-41833', 'title': 'A race condition in UEFI firmware for some Intel® processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-21871
INTEL-SA-01071
2024.3 IPU - UEFI Firmware Advisory
Potential security vulnerabilities in UEFI firmware for some Intel® Processors may allow escalation of privilege, denial of service or information disclosure. Intel is releasing UEFI firmware updates to mitigate these potential vulnerabilities.
MEDIUM
2024-09-10 03:00:00+03:00
2024-09-10 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01071.html
c4e0510c116199b8c793d54628b566d00e43e6dda89c2ab1dcce274505f72acf
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in UEFI firmware for some Intel® Processors may allow escalation of privilege, denial of service or information disclosure. Intel is releasing UEFI firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of Intel® Processors update to the latest version provided by the system manufacturer that addresses these issues.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': '2024.3 IPU - UEFI Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01071', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-09-10T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-09-10T00:00:00+00:00', 'initial_release_date': '2024-09-10T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01071.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['The following were found by Intel employees.\xa0 Intel would like to thank Ilya Alexandrovich (CVE-2023-43753) and Majid Shushtarian, Richard Thomaiyar, James Mihm, Vernon Maurey, Nilanthren (CVE-2024-23599).\r\nIntel would like to thank Phoenix Technologies (CVE-2023-43626), Yngweijw (CVE-2024-21871, CVE-2023-42772, CVE-2023-41833, CVE-2024-21829), Jeremy Boone (@uffeux) (CVE-2023-22351, CVE-2023-23904, CVE-2023-25546) for reporting these issues. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-23904', 'title': 'NULL pointer dereference in the UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-43626', 'title': 'Improper access control in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21781', 'title': 'Improper input validation in UEFI firmware for some Intel® Processors may allow a privileged user to enable information disclosure or denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:H/SC:H/SI:N/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23599', 'title': 'Race condition in Seamless Firmware Updates for some Intel® reference platforms may allow a privileged user to potentially enable denial of service via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.9, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21829', 'title': 'Improper input validation in UEFI firmware error handler for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-25546', 'title': 'Out-of-bounds read in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 2.5, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 1.8, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-43753', 'title': 'Improper conditions check in some Intel(R) Processors with Intel® Software Guard Extensions (Intel® SGX) may allow a privileged user to potentially enable information disclosure via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-42772', 'title': 'Untrusted pointer dereference in UEFI firmware for some Intel® reference processors may allow a privileged user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21871', 'title': 'Improper input validation in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-22351', 'title': 'Out-of-bounds write in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-41833', 'title': 'A race condition in UEFI firmware for some Intel® processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2023-22351
INTEL-SA-01071
2024.3 IPU - UEFI Firmware Advisory
Potential security vulnerabilities in UEFI firmware for some Intel® Processors may allow escalation of privilege, denial of service or information disclosure. Intel is releasing UEFI firmware updates to mitigate these potential vulnerabilities.
MEDIUM
2024-09-10 03:00:00+03:00
2024-09-10 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01071.html
d9df04e8cc36e3fdcdea55c84861e01d9d464df8ad752e9babe6b472b528f171
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in UEFI firmware for some Intel® Processors may allow escalation of privilege, denial of service or information disclosure. Intel is releasing UEFI firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of Intel® Processors update to the latest version provided by the system manufacturer that addresses these issues.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': '2024.3 IPU - UEFI Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01071', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-09-10T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-09-10T00:00:00+00:00', 'initial_release_date': '2024-09-10T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01071.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['The following were found by Intel employees.\xa0 Intel would like to thank Ilya Alexandrovich (CVE-2023-43753) and Majid Shushtarian, Richard Thomaiyar, James Mihm, Vernon Maurey, Nilanthren (CVE-2024-23599).\r\nIntel would like to thank Phoenix Technologies (CVE-2023-43626), Yngweijw (CVE-2024-21871, CVE-2023-42772, CVE-2023-41833, CVE-2024-21829), Jeremy Boone (@uffeux) (CVE-2023-22351, CVE-2023-23904, CVE-2023-25546) for reporting these issues. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-23904', 'title': 'NULL pointer dereference in the UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-43626', 'title': 'Improper access control in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21781', 'title': 'Improper input validation in UEFI firmware for some Intel® Processors may allow a privileged user to enable information disclosure or denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:H/SC:H/SI:N/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23599', 'title': 'Race condition in Seamless Firmware Updates for some Intel® reference platforms may allow a privileged user to potentially enable denial of service via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.9, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21829', 'title': 'Improper input validation in UEFI firmware error handler for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-25546', 'title': 'Out-of-bounds read in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 2.5, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 1.8, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-43753', 'title': 'Improper conditions check in some Intel(R) Processors with Intel® Software Guard Extensions (Intel® SGX) may allow a privileged user to potentially enable information disclosure via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-42772', 'title': 'Untrusted pointer dereference in UEFI firmware for some Intel® reference processors may allow a privileged user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21871', 'title': 'Improper input validation in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-22351', 'title': 'Out-of-bounds write in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-41833', 'title': 'A race condition in UEFI firmware for some Intel® processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2023-41833
INTEL-SA-01071
2024.3 IPU - UEFI Firmware Advisory
Potential security vulnerabilities in UEFI firmware for some Intel® Processors may allow escalation of privilege, denial of service or information disclosure. Intel is releasing UEFI firmware updates to mitigate these potential vulnerabilities.
MEDIUM
2024-09-10 03:00:00+03:00
2024-09-10 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01071.html
cd64f15d2448fcbd005dfd873fb9da33da04b52b5fbd1bd0e14e5af0a8d5e8ba
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in UEFI firmware for some Intel® Processors may allow escalation of privilege, denial of service or information disclosure. Intel is releasing UEFI firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of Intel® Processors update to the latest version provided by the system manufacturer that addresses these issues.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': '2024.3 IPU - UEFI Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01071', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-09-10T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-09-10T00:00:00+00:00', 'initial_release_date': '2024-09-10T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01071.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['The following were found by Intel employees.\xa0 Intel would like to thank Ilya Alexandrovich (CVE-2023-43753) and Majid Shushtarian, Richard Thomaiyar, James Mihm, Vernon Maurey, Nilanthren (CVE-2024-23599).\r\nIntel would like to thank Phoenix Technologies (CVE-2023-43626), Yngweijw (CVE-2024-21871, CVE-2023-42772, CVE-2023-41833, CVE-2024-21829), Jeremy Boone (@uffeux) (CVE-2023-22351, CVE-2023-23904, CVE-2023-25546) for reporting these issues. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-23904', 'title': 'NULL pointer dereference in the UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-43626', 'title': 'Improper access control in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21781', 'title': 'Improper input validation in UEFI firmware for some Intel® Processors may allow a privileged user to enable information disclosure or denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:H/SC:H/SI:N/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23599', 'title': 'Race condition in Seamless Firmware Updates for some Intel® reference platforms may allow a privileged user to potentially enable denial of service via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.9, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21829', 'title': 'Improper input validation in UEFI firmware error handler for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-25546', 'title': 'Out-of-bounds read in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 2.5, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 1.8, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-43753', 'title': 'Improper conditions check in some Intel(R) Processors with Intel® Software Guard Extensions (Intel® SGX) may allow a privileged user to potentially enable information disclosure via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-42772', 'title': 'Untrusted pointer dereference in UEFI firmware for some Intel® reference processors may allow a privileged user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21871', 'title': 'Improper input validation in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-22351', 'title': 'Out-of-bounds write in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-41833', 'title': 'A race condition in UEFI firmware for some Intel® processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-21766
INTEL-SA-01072
Intel® oneAPI Math Kernel Library Software Advisory
A potential security vulnerability in some Intel® oneAPI Math Kernel Library software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.
MEDIUM
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01072.html
c67a9ebbb4789fc06e78786726cd77989c107f17c2dd716954b3ff2debd0c081
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® oneAPI Math Kernel Library software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating Intel® oneAPI Math Kernel Library to version 2024.1 or later.\r\nUpdates are available for download at this location:\r\nhttps://www.intel.com/content/www/us/en/developer/tools/oneapi/onemkl.html#gs.43pz8i\r\n\xa0\r\nIntel recommends updating Intel® Base Toolkit to version 2024.1 or later.\r\nUpdates are available for download at this location:\r\nhttps://www.intel.com/content/www/us/en/developer/tools/oneapi/toolkits.html#base-kit', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® oneAPI Math Kernel Library Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01072', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01072.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank ycdxsb for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-21766', 'title': 'Uncontrolled search path for some Intel® oneAPI Math Kernel Library software before version 2024.1 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-22374
INTEL-SA-01073
UPLR1 - Intel® Xeon Processor Advisory
A potential security vulnerability in some Intel® Xeon Processors may allow denial of service. Intel is releasing firmware updates to mitigate this potential vulnerability.
MEDIUM
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01073.html
57965bce668074a057da17a03d1f1d4ee3f3b4f369d85141ec79e630b3f5332b
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® Xeon Processors may allow denial of service. Intel is releasing firmware updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of Intel® 4th Generation, Intel® 5th Generation and Intel® Xeon® Scalable Processors update to the latest platform provided by the system manufacturer that addresses these issues.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Hardware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Denial of Service', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'UPLR1 - Intel® Xeon Processor Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01073', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01073.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['This issue was found in partnership with an industry partner and Intel employees. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-22374', 'title': 'Insufficient control flow management for some Intel® Xeon Processors may allow an authenticated user to potentially enable denial of service via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-23491
INTEL-SA-01075
Intel® Distribution for GDB Software Advisory
Potential security vulnerabilities in some Intel® Distribution for GDB software may allow escalation of privilege or denial of service. Intel is releasing software updates to mitigate this potential vulnerability.
MEDIUM
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01075.html
0581961aba15ad3c6f7ebe67f2529b6a2d449a2e513b60d39c22e39a7047c4d3
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® Distribution for GDB software may allow escalation of privilege or denial of service. Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating Intel® Distribution for GDB software to version 2024.0.1 or later.\r\nUpdates are available for download at this location:\xa0\r\nhttps://www.intel.com/content/www/us/en/developer/articles/tool/oneapi-standalone-components.html#distributiongdb\r\n\xa0\r\nIntel recommends updating Intel® oneAPI Base Toolkit software to version 2024.1 or later.\r\nUpdates are available for download at this location:\xa0\r\nhttps://www.intel.com/content/www/us/en/developer/tools/oneapi/base-toolkit-download.html', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Distribution for GDB Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01075', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01075.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank ycdxsb (CVE-2024-23491, CVE-2024-23495, CVE-2024-24973), fuzzm3 (CVE-2024-25562) for reporting these issues. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-23491', 'title': 'Uncontrolled search path in some Intel® Distribution for GDB software before version 2024.0.1 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-25562', 'title': 'Improper buffer restrictions in some Intel® Distribution for GDB software before version 2024.0.1 may allow an authenticated user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23495', 'title': 'Incorrect default permissions in some Intel® Distribution for GDB software before version 2024.0.1 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-24973', 'title': 'Improper input validation for some Intel® Distribution for GDB software before version 2024.0.1 may allow an authenticated user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 2.2, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 1, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-25562
INTEL-SA-01075
Intel® Distribution for GDB Software Advisory
Potential security vulnerabilities in some Intel® Distribution for GDB software may allow escalation of privilege or denial of service. Intel is releasing software updates to mitigate this potential vulnerability.
MEDIUM
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01075.html
066e2896dbdaa7fc4b7f5e5d66bf5c47e69be015fa4ca4e40e8541a035e87ee8
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® Distribution for GDB software may allow escalation of privilege or denial of service. Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating Intel® Distribution for GDB software to version 2024.0.1 or later.\r\nUpdates are available for download at this location:\xa0\r\nhttps://www.intel.com/content/www/us/en/developer/articles/tool/oneapi-standalone-components.html#distributiongdb\r\n\xa0\r\nIntel recommends updating Intel® oneAPI Base Toolkit software to version 2024.1 or later.\r\nUpdates are available for download at this location:\xa0\r\nhttps://www.intel.com/content/www/us/en/developer/tools/oneapi/base-toolkit-download.html', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Distribution for GDB Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01075', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01075.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank ycdxsb (CVE-2024-23491, CVE-2024-23495, CVE-2024-24973), fuzzm3 (CVE-2024-25562) for reporting these issues. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-23491', 'title': 'Uncontrolled search path in some Intel® Distribution for GDB software before version 2024.0.1 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-25562', 'title': 'Improper buffer restrictions in some Intel® Distribution for GDB software before version 2024.0.1 may allow an authenticated user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23495', 'title': 'Incorrect default permissions in some Intel® Distribution for GDB software before version 2024.0.1 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-24973', 'title': 'Improper input validation for some Intel® Distribution for GDB software before version 2024.0.1 may allow an authenticated user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 2.2, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 1, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-23495
INTEL-SA-01075
Intel® Distribution for GDB Software Advisory
Potential security vulnerabilities in some Intel® Distribution for GDB software may allow escalation of privilege or denial of service. Intel is releasing software updates to mitigate this potential vulnerability.
MEDIUM
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01075.html
63a046243a6449a89db2e70d535d8628fcf7424e1d65f6e1aab0fefab2d497da
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® Distribution for GDB software may allow escalation of privilege or denial of service. Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating Intel® Distribution for GDB software to version 2024.0.1 or later.\r\nUpdates are available for download at this location:\xa0\r\nhttps://www.intel.com/content/www/us/en/developer/articles/tool/oneapi-standalone-components.html#distributiongdb\r\n\xa0\r\nIntel recommends updating Intel® oneAPI Base Toolkit software to version 2024.1 or later.\r\nUpdates are available for download at this location:\xa0\r\nhttps://www.intel.com/content/www/us/en/developer/tools/oneapi/base-toolkit-download.html', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Distribution for GDB Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01075', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01075.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank ycdxsb (CVE-2024-23491, CVE-2024-23495, CVE-2024-24973), fuzzm3 (CVE-2024-25562) for reporting these issues. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-23491', 'title': 'Uncontrolled search path in some Intel® Distribution for GDB software before version 2024.0.1 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-25562', 'title': 'Improper buffer restrictions in some Intel® Distribution for GDB software before version 2024.0.1 may allow an authenticated user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23495', 'title': 'Incorrect default permissions in some Intel® Distribution for GDB software before version 2024.0.1 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-24973', 'title': 'Improper input validation for some Intel® Distribution for GDB software before version 2024.0.1 may allow an authenticated user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 2.2, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 1, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-24973
INTEL-SA-01075
Intel® Distribution for GDB Software Advisory
Potential security vulnerabilities in some Intel® Distribution for GDB software may allow escalation of privilege or denial of service. Intel is releasing software updates to mitigate this potential vulnerability.
MEDIUM
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01075.html
a0c95f2625451721ade8f8b49344e42ddf245e2e39d2f21f7c905858567da613
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® Distribution for GDB software may allow escalation of privilege or denial of service. Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating Intel® Distribution for GDB software to version 2024.0.1 or later.\r\nUpdates are available for download at this location:\xa0\r\nhttps://www.intel.com/content/www/us/en/developer/articles/tool/oneapi-standalone-components.html#distributiongdb\r\n\xa0\r\nIntel recommends updating Intel® oneAPI Base Toolkit software to version 2024.1 or later.\r\nUpdates are available for download at this location:\xa0\r\nhttps://www.intel.com/content/www/us/en/developer/tools/oneapi/base-toolkit-download.html', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Distribution for GDB Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01075', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01075.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank ycdxsb (CVE-2024-23491, CVE-2024-23495, CVE-2024-24973), fuzzm3 (CVE-2024-25562) for reporting these issues. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-23491', 'title': 'Uncontrolled search path in some Intel® Distribution for GDB software before version 2024.0.1 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-25562', 'title': 'Improper buffer restrictions in some Intel® Distribution for GDB software before version 2024.0.1 may allow an authenticated user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23495', 'title': 'Incorrect default permissions in some Intel® Distribution for GDB software before version 2024.0.1 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-24973', 'title': 'Improper input validation for some Intel® Distribution for GDB software before version 2024.0.1 may allow an authenticated user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 2.2, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 1, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-21850
INTEL-SA-01076
Intel® TDX Seamldr Software Advisory
A potential security vulnerability in some Intel® TDX Seamldr module software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerabilty.
MEDIUM
2024-11-12 03:00:00+03:00
2024-11-12 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01076.html
8dee903fb94b08b9772c2b994b87214731776dbfbf6aadb9ba9c702dd47f51fc
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® TDX Seamldr module software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerabilty. ', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating to SEAMLDR version 1.5.02.00, available in Unified Post Launch Release 1 (UPLR1).', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Hardware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® TDX Seamldr Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01076', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-11-12T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-11-12T00:00:00+00:00', 'initial_release_date': '2024-11-12T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01076.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Copyright © Intel Corporation All rights reserved.'}, 'acknowledgments': [{'names': ['This issue was found internally by Intel employees. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-21850', 'cwe': {'id': 'CWE-226', 'name': 'Sensitive Information in Resource Not Removed Before Reuse'}, 'title': 'Sensitive information in resource not removed before reuse in some Intel® TDX Seamldr module software before version 1.5.02.00 may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'HIGH', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.3, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'HIGH', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'NONE', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2023-49144
INTEL-SA-01078
UPLR1 - OpenBMC Firmware Advisory
Potential security vulnerabilities in OpenBMC Firmware for some Intel® Server Platforms may allow information disclosure or denial of service. Intel is releasing firmware updates to mitigate these potential vulnerabilities.
MEDIUM
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01078.html
600687cf5db56245425e9b14ab6bf0343b61c65ed009fd78a28dd36840d37965
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in OpenBMC Firmware for some Intel® Server Platforms may allow information disclosure or denial of service. Intel is releasing firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users update to the latest version provided by the system manufacturer that addresses these issues.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'UPLR1 - OpenBMC Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01078', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01078.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['CVE-2023-49144 was found internally by Intel employees. Intel would like to thank Daniel Medina Velazquez and Thierry Fernandes Faria.\xa0\r\nCVE-2023-35123 was found internally by Intel employees. Intel would like to thank Alexander Gutkin, Cezary Golder and Boris Chernis. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-49144', 'title': 'Out of bounds read in OpenBMC Firmware for some Intel® Server Platforms before versions egs-1.15-0, bhs-0.27 may allow a privileged user to potentially enable information disclosure via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.1, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-35123', 'title': 'Uncaught exception in OpenBMC Firmware for some Intel® Server Platforms before versions egs-1.14-0, bhs-0.27 may allow an authenticated user to potentially enable denial of service via network access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2023-35123
INTEL-SA-01078
UPLR1 - OpenBMC Firmware Advisory
Potential security vulnerabilities in OpenBMC Firmware for some Intel® Server Platforms may allow information disclosure or denial of service. Intel is releasing firmware updates to mitigate these potential vulnerabilities.
MEDIUM
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01078.html
eaf829648d3b5cf05e99fd2221bd545397799135fcb4ba35f35960729ce0936d
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in OpenBMC Firmware for some Intel® Server Platforms may allow information disclosure or denial of service. Intel is releasing firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users update to the latest version provided by the system manufacturer that addresses these issues.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'UPLR1 - OpenBMC Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01078', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01078.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['CVE-2023-49144 was found internally by Intel employees. Intel would like to thank Daniel Medina Velazquez and Thierry Fernandes Faria.\xa0\r\nCVE-2023-35123 was found internally by Intel employees. Intel would like to thank Alexander Gutkin, Cezary Golder and Boris Chernis. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-49144', 'title': 'Out of bounds read in OpenBMC Firmware for some Intel® Server Platforms before versions egs-1.15-0, bhs-0.27 may allow a privileged user to potentially enable information disclosure via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.1, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-35123', 'title': 'Uncaught exception in OpenBMC Firmware for some Intel® Server Platforms before versions egs-1.14-0, bhs-0.27 may allow an authenticated user to potentially enable denial of service via network access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-21820
INTEL-SA-01079
Intel® Xeon® Processor with Intel® SGX Advisory
Potential security vulnerabilities in some Intel® Xeon® processors using Intel® Software Guard Extensions (Intel SGX) may allow escalation of privilege. Intel is releasing firmware updates to mitigate these potential vulnerabilities.
HIGH
2024-11-12 03:00:00+03:00
2024-11-12 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01079.html
aace0d03075cb9cbaf54a4c504e99054c735af34fa3f75c7e933abe46ee9dfd5
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® Xeon® processors using Intel® Software Guard Extensions (Intel SGX) may allow escalation of privilege. Intel is releasing firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of the Intel® SGX module update to the latest version provided by the system manufacturer that addresses this issue.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Hardware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Xeon® Processor with Intel® SGX Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01079', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-11-12T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-11-12T00:00:00+00:00', 'initial_release_date': '2024-11-12T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01079.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Copyright © Intel Corporation All rights reserved.'}, 'acknowledgments': [{'names': ['This issue was found internally by Intel. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-21820', 'cwe': {'id': 'CWE-276', 'name': 'Incorrect Default Permissions'}, 'title': 'Incorrect default permissions in some Intel® Xeon® processor memory controller configurations when using Intel® SGX may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 7.2, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'availabilityImpact': 'NONE', 'privilegesRequired': 'HIGH', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.5, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'privilegesRequired': 'HIGH', 'subIntegrityImpact': 'HIGH', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'NONE', 'subConfidentialityImpact': 'HIGH', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23918', 'cwe': {'id': 'CWE-754', 'name': 'Improper Check for Unusual or Exceptional Conditions'}, 'title': 'Improper conditions check in some Intel® Xeon® processor memory controller configurations when using Intel® SGX may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'HIGH', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'HIGH', 'vulnAvailabilityImpact': 'HIGH', 'subConfidentialityImpact': 'HIGH', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-23918
INTEL-SA-01079
Intel® Xeon® Processor with Intel® SGX Advisory
Potential security vulnerabilities in some Intel® Xeon® processors using Intel® Software Guard Extensions (Intel SGX) may allow escalation of privilege. Intel is releasing firmware updates to mitigate these potential vulnerabilities.
HIGH
2024-11-12 03:00:00+03:00
2024-11-12 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01079.html
b68096d7e820ab0926fbc9856feabecc1b9615982a36fb9648f4089ffbcf7b95
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® Xeon® processors using Intel® Software Guard Extensions (Intel SGX) may allow escalation of privilege. Intel is releasing firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of the Intel® SGX module update to the latest version provided by the system manufacturer that addresses this issue.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Hardware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Xeon® Processor with Intel® SGX Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01079', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-11-12T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-11-12T00:00:00+00:00', 'initial_release_date': '2024-11-12T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01079.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Copyright © Intel Corporation All rights reserved.'}, 'acknowledgments': [{'names': ['This issue was found internally by Intel. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-21820', 'cwe': {'id': 'CWE-276', 'name': 'Incorrect Default Permissions'}, 'title': 'Incorrect default permissions in some Intel® Xeon® processor memory controller configurations when using Intel® SGX may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 7.2, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'availabilityImpact': 'NONE', 'privilegesRequired': 'HIGH', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.5, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'privilegesRequired': 'HIGH', 'subIntegrityImpact': 'HIGH', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'NONE', 'subConfidentialityImpact': 'HIGH', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23918', 'cwe': {'id': 'CWE-754', 'name': 'Improper Check for Unusual or Exceptional Conditions'}, 'title': 'Improper conditions check in some Intel® Xeon® processor memory controller configurations when using Intel® SGX may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'HIGH', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'HIGH', 'vulnAvailabilityImpact': 'HIGH', 'subConfidentialityImpact': 'HIGH', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-24853
INTEL-SA-01083
2024.3 IPU - SMI Transfer Monitor Advisory
A potential security vulnerability in SMI Transfer monitor (STM) may allow escalation of privilege. Intel is releasing microcode updates to mitigate this potential vulnerability.
HIGH
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01083.html
37545b094a8610b3dc52622762024846b975e3f4a41f8478b4be171a03e10707
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in SMI Transfer monitor (STM) may allow escalation of privilege. Intel is releasing microcode updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of affected Intel® Processors update to the latest firmware provided by the system manufacturer that addresses this issue.\r\nIntel has released microcode update for the affected products that are currently supported on the public github repository.\r\nPlease see details below on access to the microcode:Public Github: \xa0https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files.\r\nThe microcode patch can be OS loaded.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Hardware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': '2024.3 IPU - SMI Transfer Monitor Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01083', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01083.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['This issue was discovered internally by Intel employees. Intel would like to thank Ezra Caltum for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-24853', 'title': 'Incorrect behavior order in transition between executive monitor and SMI transfer monitor (STM) in some Intel® Processor may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-25565
INTEL-SA-01085
Intel® UEFI Firmware Advisory
A potential security vulnerability in UEFI firmware for some Intel® Xeon® Processors may allow denial of service. Intel is releasing firmware updates to mitigate this potential vulnerability.
LOW
2024-11-12 03:00:00+03:00
2024-11-12 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01085.html
9c8460cfd816d6f2d1a0d0147f464b1f2aac50560269b29da7700c31788afb2f
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in UEFI firmware for some Intel® Xeon® Processors may allow denial of service. Intel is releasing firmware updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of 4th and 5th Generation Intel® Xeon® Scalable Processors update to the latest version provided by the system manufacturer that addresses these issues.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Low', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Denial of Service', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® UEFI Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01085', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-11-12T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-11-12T00:00:00+00:00', 'initial_release_date': '2024-11-12T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01085.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Copyright © Intel Corporation All rights reserved.'}, 'acknowledgments': [{'names': ['This issue was found internally by Intel employees. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-25565', 'cwe': {'id': 'CWE-691', 'name': 'Insufficient Control Flow Management'}, 'title': 'Insufficient control flow management in UEFI firmware for some Intel® Xeon® Processors may allow an authenticated user to enable denial of service via local access. ', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 3.8, 'attackVector': 'LOCAL', 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'cvss_v4': {'version': '4.0', 'baseScore': 4.8, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'NONE', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'LOW', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'NONE'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-25576
INTEL-SA-01087
Intel Agilex® FPGA Firmware Advisory
A potential security vulnerability in some Intel Agilex® FPGA Firmware may allow escalation of privilege. Intel is releasing firmrware updates to mitigate this potential vulnerability.
HIGH
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01087.html
63cdaaa41a9077b82f2e424321bdd04ff0f50142c54527d912862ad7a3cd62b3
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel Agilex® FPGA Firmware may allow escalation of privilege. Intel is releasing firmrware updates to mitigate this potential vulnerability. ', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating Intel Agilex® FPGA 7 FPGA firmware to version 24.1 or later.\r\nUpdates are available for download at this location:\xa0FPGA software', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel Agilex® FPGA Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01087', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01087.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['This issue was found internally by Intel. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-25576', 'title': 'improper access control in firmware for some Intel(R) FPGA products before version 24.1 may allow a privileged user to enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.9, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-23974
INTEL-SA-01088
Intel® ISH Software Installer Advisory
A potential security vulnerability in some Intel® Integrated Sensor Hub (ISH) software installers may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.
MEDIUM
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01088.html
1d018797be59f35a1873b24fe224f3fd40dbe3e44d087396d123c15efb017e4d
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® Integrated Sensor Hub (ISH) software installers may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of Intel® ISH software installers for Intel® Core™ Processor Family update to the latest version provided by the system manufacturer that addresses these issues. \xa0\r\nUpdates for NUC are available for download at these locations:\r\nIntel® NUC M15 Laptop Kits LAPBC710 and LAPBC510:\r\nhttps://www.intel.com/content/www/us/en/download/19731\r\nIntel® NUC M15 Laptop Kits LAPRC710 and LAPRC510:\r\nhttps://www.intel.com/content/www/us/en/download/736480\r\nProduct support for many NUC products has moved to ASUS. Technical and Warranty Support for Intel’s NUC 7 through NUC 13 Systems has transitioned to ASUS as of January 16, 2024. See the NUC Customer Support notice\xa0for more information.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® ISH Software Installer Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01088', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01088.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['This issue was found internally by Intel. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-23974', 'title': 'Incorrect default permissions in some Intel® ISH software installers may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-25561
INTEL-SA-01089
Intel® HID Event Filter Software Installer Advisory
A potential security vulnerability in some Intel® Human Interface Device (HID) Event Filter software installers may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.
MEDIUM
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01089.html
0871e9361580d067585d8b2fa6273bffb2fe3d2610c08f9cf727868ca97813b9
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® Human Interface Device (HID) Event Filter software installers may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of Intel® HID Event Filter software installers update to the latest version provided by the system manufacturer that addresses these issues.Updates are available for Intel® NUC M15 or X15 Laptop Kits at this download location:https://www.intel.com/content/www/us/en/download/19820Product support for many NUC products has moved to ASUS. Technical and Warranty Support for Intel's NUC 7 through NUC 13 Systems has transitioned to ASUS as of January 16, 2024.\xa0See the\xa0NUC Customer Support notice\xa0for more information.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® HID Event Filter Software Installer Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01089', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01089.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank hamdi @falconCorrup and Mohamed amine saidani for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-25561', 'title': 'Insecure inherited permissions in some Intel® HID Event Filter software installers before version 2.2.2.1 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-24580
INTEL-SA-01094
Intel® Data Center GPU Max Series Advisory
A potential security vulnerability in some Intel® Data Center GPU Max Series 1100 and 1550 products may allow denial of service. Intel is releasing prescriptive guidance to address this potential vulnerability.
MEDIUM
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01094.html
31deda634f460d9852e6592b65db2d296ca7ea0484e098097fc53a352a3bb9e2
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® Data Center GPU Max Series 1100 and 1550 products may allow denial of service. Intel is releasing prescriptive guidance to address this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends users follow existing security best practices and alternate security controls, including:Intel® Data Center GPU Max Series 1100 and 1550\xa0Intel(r) Data Center GPU Max Configuration Recommendation.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Hardware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Denial of Service', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Data Center GPU Max Series Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01094', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01094.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['This issue was found internally by Intel employees. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-24580', 'title': 'Improper conditions check in some Intel® Data Center GPU Max Series 1100 and 1550 products may allow a privileged user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-22378
INTEL-SA-01095
Intel Unite® Client Software Installer Advisory
A potential security vulnerability in some Intel Unite® Client software installers may allow escalation of privilege. Intel is not releasing updates to mitigate this potential vulnerability and has issued a Product Discontinuation Notice for Intel Unite® Client software.
MEDIUM
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01095.html
97a36f6169ca1e5091e87b19868540679d3d6aa92810f8649fddd0be2529fedf
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel Unite® Client software installers may allow escalation of privilege. Intel is not releasing updates to mitigate this potential vulnerability and has issued a Product Discontinuation Notice for Intel Unite® Client software.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel has issued a\xa0Product Discontinuation Notice\xa0for Intel Unite® Client software and recommends that users of the Intel Unite® software uninstall it or discontinue use at their earliest convenience.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel Unite® Client Software Installer Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01095', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01095.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank ycdxsb and @sim0nsecurity for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-22378', 'title': 'Incorrect default permissions in some Intel Unite® Client Extended Display Plugin software installers before version 1.1.352.157 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-24968
INTEL-SA-01097
2024.3 IPU - Intel® Processor Advisory
A potential security vulnerability in some Intel® Processors may allow denial of service. Intel is releasing firmware updates to mitigate this potential vulnerability.
MEDIUM
2024-09-10 03:00:00+03:00
2024-09-10 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01097.html
cbdeeddb8e7ad03362913eaf383944ae6a7ee9ec8555b6ff3245e4abd2cd6d2d
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® Processors may allow denial of service. Intel is releasing firmware updates to mitigate this potential vulnerability. ', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updated microcode to the latest version provided by your system manufacturer.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Hardware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Denial of Service', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': '2024.3 IPU - Intel® Processor Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01097', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-09-10T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-09-10T00:00:00+00:00', 'initial_release_date': '2024-09-10T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01097.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['This issue was found internally by Intel employees. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-24968', 'title': 'Improper finite state machines (FSMs) in hardware logic in some Intel® Processors may allow an privileged user to potentially enable a denial of service via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.6, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-27457
INTEL-SA-01099
Intel® TDX Module Software Advisory
A potential security vulnerability in Intel® Trust Domain Extensions (TDX) Module firmware may allow information disclosure. Intel is releasing firmware updates to mitigate this potential vulnerability.
LOW
2024-10-08 03:00:00+03:00
2024-10-08 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01099.html
2b8ddd579136bf28b20eb5b4996e343ec8a36bb5e0982a33b20582bfacce1659
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in Intel® Trust Domain Extensions (TDX) Module firmware may allow information disclosure. Intel is releasing firmware updates to mitigate this potential vulnerability. ', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of the Intel® TDX module update to the latest version provided by the system manufacturer that addresses this issue.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Low', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Hardware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® TDX Module Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01099', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-10-08T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-10-08T00:00:00+00:00', 'initial_release_date': '2024-10-08T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01099.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Copyright © Intel Corporation All rights reserved.'}, 'acknowledgments': [{'names': ['Intel would like to thank Luka Wilke,\xa0 Florian Sieck, and Thomas Eisenbarth from the University of Lübeck for reporting this issue to Intel. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-27457', 'cwe': {'id': 'CWE-754', 'name': 'Improper Check for Unusual or Exceptional Conditions'}, 'title': 'Improper check for unusual or exceptional conditions in Intel® TDX Module firmware before version 1.5.06 may allow a privileged user to potentially enable information disclosure via local access. ', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 2.5, 'attackVector': 'LOCAL', 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'availabilityImpact': 'NONE', 'privilegesRequired': 'HIGH', 'confidentialityImpact': 'LOW'}, 'cvss_v4': {'version': '4.0', 'baseScore': 1.8, 'attackVector': 'LOCAL', 'baseSeverity': 'LOW', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'attackRequirements': 'NONE', 'privilegesRequired': 'HIGH', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'NONE', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'NONE', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'LOW'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-24980
INTEL-SA-01100
2024.3 IPU - Intel® Xeon® Processor Advisory
A potential security vulnerability in some 3rd, 4th, and 5th Generation Intel® Xeon® Processors may allow escalation of privilege. Intel is releasing firmware updates to mitigate this potential vulnerability.
MEDIUM
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01100.html
79c504683c15b23b4400f148748473937f390a7e2f55cf173e7630de0ffc4979
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some 3rd, 4th, and 5th Generation Intel® Xeon® Processors may allow escalation of privilege. Intel is releasing firmware updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of Intel® 3rd, 4th and 5th Generation Intel® Xeon® Scalable Processors update to the latest version provided by the system manufacturer that addresses these issues.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Hardware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': '2024.3 IPU - Intel® Xeon® Processor Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01100', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01100.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['This issue was found internally by Intel employees. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-24980', 'title': ' Protection mechanism failure in some 3rd, 4th, and 5th Generation Intel® Xeon® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:H/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:L/SI:H/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-21853
INTEL-SA-01101
Intel® Xeon® Processor Advisory
A potential security vulnerability in some 4th and 5th Generation Intel® Xeon® Processors may allow denial of service. Intel is releasing microcode updates to mitigate this potential vulnerability.
MEDIUM
2024-11-12 03:00:00+03:00
2024-11-12 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01101.html
800b8d7233d0fb658343b600c5bd82432599f1b8d8e3ff28a2daa65d3640ff2c
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some 4th and 5th Generation Intel® Xeon® Processors may allow denial of service. Intel is releasing microcode updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating 4th and 5th Generation Intel® Xeon® Scalable Processors with the latest firmware provided by the OEM.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Hardware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Denial of Service', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Xeon® Processor Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01101', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-11-12T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-11-12T00:00:00+00:00', 'initial_release_date': '2024-11-12T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01101.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Copyright © Intel Corporation All rights reserved.'}, 'acknowledgments': [{'names': ['This issue was found internally by Intel employees. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-21853', 'cwe': {'id': 'CWE-1245', 'name': 'Improper Finite State Machines (FSMs) in Hardware Logic'}, 'title': 'Faulty finite state machines (FSMs) in the hardware logic in some 4th and 5th Generation Intel® Xeon® Processors may allow an authorized user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 4.7, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.7, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'attackRequirements': 'NONE', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'NONE', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'HIGH', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'NONE'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2023-43747
INTEL-SA-01102
Intel® Connectivity Performance Suite Software Installer Advisory
A potential security vulnerability in some Intel® Connectivity Performance Suite software installers may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.
MEDIUM
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01102.html
20923a1c9eacf6057a5c1dd371335898b7d27230ec7e9abd76c089118b1ab2c4
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® Connectivity Performance Suite software installers may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating Intel® Connectivity Performance Suite software to version 30.24.144 or later.\r\nUpdates are available for download at this location:\xa0\r\nhttps://www.intel.com/content/www/us/en/download/738623', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Connectivity Performance Suite Software Installer Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01102', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01102.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank Mohamed amine saidani for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-43747', 'title': 'Incorrect default permissions for some Intel® Connectivity Performance Suite software installers before version 2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-23984
INTEL-SA-01103
2024.3 IPU - Intel® Processor RAPL Interface Advisory
A potential security vulnerability in the Running Average Power Limit (RAPL) interface for some Intel® Processors may allow information disclosure. Intel is releasing firmware updates to mitigate this potential vulnerability.
MEDIUM
2024-09-10 03:00:00+03:00
2024-09-10 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01103.html
dca52ac55ed8276f62a9af68be1c4499ae819b471fd82a9b3fa52ff13cda03a5
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in the Running Average Power Limit (RAPL) interface for some Intel® Processors may allow information disclosure. Intel is releasing firmware updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of some Intel® Processor RAPL interfaces update to the latest firmware version provided by the system manufacturer that addresses these issues.\r\nFor additional information or guidance about the RAPL issue please see the RAPL guidance: Running Average Power Limit Energy Reporting', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Hardware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': '2024.3 IPU - Intel® Processor RAPL Interface Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01103', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-09-10T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-09-10T00:00:00+00:00', 'initial_release_date': '2024-09-10T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01103.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['This issue was found by Intel employees. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-23984', 'title': 'Observable discrepancy in RAPL interface for some Intel® Processors may allow a privileged user to potentially enable information disclosure via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-23909
INTEL-SA-01104
Intel® FPGA SDK for OpenCL™ Software Technology Advisory
A potential security vulnerability in some Intel® FPGA SDK for OpenCL™ software technology may allow escalation of privilege. Intel is not releasing updates to mitigate this potential vulnerability and has issued a Product Discontinuation Notice for Intel® FPGA SDK for OpenCL™ software technology.
MEDIUM
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01104.html
1fefb69c78835b56301480fd0d960490cca46726c764910c648476d7f72ce485
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® FPGA SDK for OpenCL™ software technology may allow escalation of privilege. Intel is not releasing updates to mitigate this potential vulnerability and has issued a Product Discontinuation Notice for Intel® FPGA SDK for OpenCL™ software technology.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel has issued a product discontinuation notice for Intel® FPGA SDK for OpenCL™ software technology and recommends that users of the Intel® FPGA SDK for OpenCL™ software technology migrate to Intel® FPGA Add-on for oneAPI Base Toolkit at their earliest convenience.\r\nUpdates are available for download at this location:\r\nIntel® FPGA Add-on for oneAPI Base Toolkit:https://www.intel.com/content/www/us/en/developer/tools/oneapi/fpga.html', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® FPGA SDK for OpenCL™ Software Technology Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01104', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01104.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank ycdxsb for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-23909', 'title': 'Uncontrolled search path in some Intel® FPGA SDK for OpenCL™ software technology may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-28046
INTEL-SA-01105
Intel® GPA Software Advisory
A potential security vulnerability in some Intel® Graphics Performance Analyzers (Intel® GPA) software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.
MEDIUM
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01105.html
e280562c4faa8bb70937552bce5e896104db611172ed29b0a77e0d28883b2b35
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® Graphics Performance Analyzers (Intel® GPA) software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating Intel® GPA software to version 2024.1 or later.\r\nUpdates are available for download at this location:\r\nhttps://www.intel.com/content/www/us/en/developer/tools/graphics-performance-analyzers/download.html', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® GPA Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01105', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01105.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank Mohamed amine Saidani for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-28046', 'title': 'Uncontrolled search path in some Intel® GPA software before version 2024.1 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-22376
INTEL-SA-01106
Intel® Ethernet Adapter Driver Pack Software Installer Advisory
A potential security vulnerability in some Intel® Ethernet Adapter Driver Pack software installers may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.
MEDIUM
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01106.html
0aba5ebec67f8a850bcfd921339e32dedd3278bb060fb6cb28a2ff55b8ce278e
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® Ethernet Adapter Driver Pack software installers may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating Intel® Ethernet Adapter Complete Driver Pack software to version 28.3 or later.\r\nUpdates are available for download at this location:\xa0https://www.intel.com/content/www/us/en/download/15084/intel-ethernet-adapter-complete-driver-pack.html', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Ethernet Adapter Driver Pack Software Installer Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01106', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01106.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank Mohamed amine saidani for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-22376', 'title': 'Uncontrolled search path element in some installation software for Intel® Ethernet Adapter Driver Pack before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-23908
INTEL-SA-01107
Flexlm License Daemons for Intel® FPGA Software Advisory
A potential security vulnerability in some Flexlm License Daemons for Intel® FPGA may allow escalation of privilege. Intel is releasing updates to mitigate this potential vulnerability.
MEDIUM
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01107.html
ad82359c60d2b2bb4ed39f82ef33916a9138974c183781d921a59bf6d2766388
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Flexlm License Daemons for Intel® FPGA may allow escalation of privilege. Intel is releasing updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating Flexlm License Daemons for Intel® FPGA Software to version v11.19.5.0 later.\r\nUpdates are available for download at this location:\xa0https://www.intel.com/content/www/us/en/software-kit/709649/flexlm-license-daemons-for-intel-fpga-software.html', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Flexlm License Daemons for Intel® FPGA Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01107', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01107.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank Falcon Corruption @falconCorrup for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-23908', 'title': 'Insecure inherited permissions in some Flexlm License Daemons for Intel® FPGA software before version v11.19.5.0 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-26025
INTEL-SA-01110
Intel® Advisor Software Advisory
A potential security vulnerability in some Intel® Advisor software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.
MEDIUM
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01110.html
37facb4fdd01e501fa72e496ca0ccb62556c05773b3eb44551c429377dc15dc7
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® Advisor software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating Intel® Advisor to version 2024.1 or later.\r\nUpdates are available for download at this location:\xa0\r\nhttps://www.intel.com/content/www/us/en/developer/articles/tool/oneapi-standalone-components.html#advisor\r\n\xa0\r\nIntel recommends updating Intel® oneAPI Base Toolkit to version 2024.1 or later.\r\nUpdates are available for download at this location:\xa0\r\nhttps://www.intel.com/content/www/us/en/developer/tools/oneapi/toolkits.html#base-kit', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Advisor Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01110', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01110.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank ycdxsb for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-26025', 'title': 'Incorrect default permissions for some Intel® Advisor software before version 2024.1 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-24985
INTEL-SA-01111
Intel® ACTM Module Software Advisory
Potential security vulnerabilities in some Intel® processors with Intel® Alias Checking Trusted Module (Intel® ACTM) may allow escalation of privilege. Intel is releasing firmware updates to mitigate these potential vulnerabilities.
HIGH
2024-11-12 03:00:00+03:00
2024-11-12 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01111.html
42bf54e1a17b31c307ce57c78e74c244ebf0c6ac2e9699fd43f8e7d10e92a65d
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® processors with Intel® Alias Checking Trusted Module (Intel® ACTM) may allow escalation of privilege. Intel is releasing firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of the Intel® ACTM module update to the latest version provided by the system manufacturer that addresses this issue.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Hardware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® ACTM Module Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01111', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-11-12T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-11-12T00:00:00+00:00', 'initial_release_date': '2024-11-12T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01111.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Copyright © Intel Corporation All rights reserved.'}, 'acknowledgments': [{'names': ['These issues were found internally by Intel. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-24985', 'cwe': {'id': 'CWE-668', 'name': 'Exposure of Resource to Wrong Sphere'}, 'title': 'Exposure of resource to wrong sphere in some Intel® processors with Intel® ACTM may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 7.2, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'availabilityImpact': 'NONE', 'privilegesRequired': 'HIGH', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.5, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'privilegesRequired': 'HIGH', 'subIntegrityImpact': 'HIGH', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'NONE', 'subConfidentialityImpact': 'HIGH', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-22185', 'cwe': {'id': 'CWE-367', 'name': 'Time-of-check Time-of-use (TOCTOU) Race Condition'}, 'title': 'Time-of-check Time-of-use Race Condition in some Intel® processors with Intel® ACTM may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 7.2, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'availabilityImpact': 'NONE', 'privilegesRequired': 'HIGH', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.5, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'privilegesRequired': 'HIGH', 'subIntegrityImpact': 'HIGH', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'NONE', 'subConfidentialityImpact': 'HIGH', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-22185
INTEL-SA-01111
Intel® ACTM Module Software Advisory
Potential security vulnerabilities in some Intel® processors with Intel® Alias Checking Trusted Module (Intel® ACTM) may allow escalation of privilege. Intel is releasing firmware updates to mitigate these potential vulnerabilities.
HIGH
2024-11-12 03:00:00+03:00
2024-11-12 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01111.html
864bc8d3a47d5c10ff4d18ec941a4efb6162133688645f5c958cd730a0f21e67
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® processors with Intel® Alias Checking Trusted Module (Intel® ACTM) may allow escalation of privilege. Intel is releasing firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of the Intel® ACTM module update to the latest version provided by the system manufacturer that addresses this issue.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Hardware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® ACTM Module Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01111', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-11-12T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-11-12T00:00:00+00:00', 'initial_release_date': '2024-11-12T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01111.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Copyright © Intel Corporation All rights reserved.'}, 'acknowledgments': [{'names': ['These issues were found internally by Intel. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-24985', 'cwe': {'id': 'CWE-668', 'name': 'Exposure of Resource to Wrong Sphere'}, 'title': 'Exposure of resource to wrong sphere in some Intel® processors with Intel® ACTM may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 7.2, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'availabilityImpact': 'NONE', 'privilegesRequired': 'HIGH', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.5, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'privilegesRequired': 'HIGH', 'subIntegrityImpact': 'HIGH', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'NONE', 'subConfidentialityImpact': 'HIGH', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-22185', 'cwe': {'id': 'CWE-367', 'name': 'Time-of-check Time-of-use (TOCTOU) Race Condition'}, 'title': 'Time-of-check Time-of-use Race Condition in some Intel® processors with Intel® ACTM may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 7.2, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'availabilityImpact': 'NONE', 'privilegesRequired': 'HIGH', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.5, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'privilegesRequired': 'HIGH', 'subIntegrityImpact': 'HIGH', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'NONE', 'subConfidentialityImpact': 'HIGH', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2023-43489
INTEL-SA-01112
Intel® CIP Software Advisory
A potential security vulnerability in some Intel® Computing Improvement Program (Intel® CIP) may allow denial of service. Intel is releasing software updates to mitigate this potential vulnerability.
MEDIUM
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01112.html
6373b04bf0b3dd55df508b1381ab07b11bd10cf04210fe9517e68263771adb76
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® Computing Improvement Program (Intel® CIP) may allow denial of service. Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating Intel® CIP software to version 2.4.10717 \xa0or later.\r\nUpdates are available for download at this location:\r\nhttps://www.intel.com/content/www/us/en/support/topics/idsa-cip.html', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Denial of Service', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® CIP Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01112', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01112.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank ycdxsb for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-43489', 'title': 'Improper access control for some Intel® CIP software before version 2.4.10717 may allow an authenticated user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-23907
INTEL-SA-01113
Intel® High Level Synthesis Compiler Software Advisory
A potential security vulnerability in some Intel® High Level Synthesis Compiler software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.
MEDIUM
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01113.html
91c0f4d1e97a5aecab62849b4698ba2bfb91eda1c93a968afd46905c3e972f13
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® High Level Synthesis Compiler software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating Intel® High Level Synthesis Compiler to version 23.4 or later.\r\nUpdates are available for download at this location:\r\nhttps://cdrdv2.intel.com/v1/dl/getContent/794625/794651?filename=HLSProSetup-23.4.0.79-windows.exe\r\n\xa0\r\nIntel recommends updating Intel® Quartus® Prime Pro Edition Design Software to version 23.4 or later.\r\nUpdates are available for download at this location:\r\nhttps://www.intel.com/content/www/us/en/software-kit/794624/intel-quartus-prime-pro-edition-design-software-version-23-4-for-linux.html\r\n\xa0\r\nIntel recommends updating Intel® DPC++ C++ Compiler software to version 2024.1 or later.\r\nUpdates are available for download at this location:\r\nhttps://www.intel.com/content/www/us/en/developer/articles/tool/oneapi-standalone-components.html#dpcpp-cpp', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® High Level Synthesis Compiler Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01113', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01113.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank ycdxsb for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-23907', 'title': 'Uncontrolled search path in some Intel® High Level Synthesis Compiler software before version 23.4 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-21784
INTEL-SA-01114
Intel® IPP Cryptography Software Advisory
A potential security vulnerability in some Intel® Integrated Performance Primitives Cryptography (Intel® IPP Cryptography) software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.
MEDIUM
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01114.html
d271402ea7f24ac84cd67e70a8e9471a91112ff6ab3b8f9b5b9647f9da730dfe
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® Integrated Performance Primitives Cryptography (Intel® IPP Cryptography) software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating Intel® Integrated Performance Primitives Cryptography software to version 2021.11 or later.\r\nUpdates are available for download at this location:\r\nhttps://www.intel.com/content/www/us/en/docs/ipp-crypto/developer-guide-reference/2021-9/overview.html\r\n\xa0\r\nIntel recommends updating Intel® oneAPI Base Toolkit to version 2024.1 or later.\r\nUpdates are available for download at this location:\r\nhttps://www.intel.com/content/www/us/en/developer/tools/oneapi/toolkits.html#base-kit', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® IPP Cryptography Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01114', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01114.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank ycdxsb for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-21784', 'title': 'Uncontrolled search path for some Intel® IPP Cryptography software before version 2021.11 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-28876
INTEL-SA-01115
Intel® MPI Library Software Advisory
A potential security vulnerability in some Intel® MPI Library software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.
MEDIUM
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01115.html
2ca375bc49e585ac0def3c840ce572880944f14f2533f8be919d4619b5472b95
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® MPI Library software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating Intel® MPI Library software to version 2021.12 or later.\xa0\r\nUpdates are available for download at this location:\r\nhttps://www.intel.com/content/www/us/en/developer/articles/tool/oneapi-standalone-components.html#mpi\r\n\xa0\r\nIntel recommends updating Intel® oneAPI HPC Toolkit to version 2024.1 or later.\r\nUpdates are available for download at this location:\r\nhttps://www.intel.com/content/www/us/en/developer/tools/oneapi/toolkits.html#hpc-kit', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® MPI Library Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01115', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01115.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank ycdxsb for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-28876', 'title': 'Uncontrolled search path for some Intel® MPI Library software before version 2021.12 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-26027
INTEL-SA-01116
Intel® Simics Package Manager Software Advisory
A potential security vulnerability in some Intel® Simics Package Manager software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.
MEDIUM
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01116.html
e36256a0763f2d6ad2efac5558b78dec4a240f7757df956c220b63f00e8aaa95
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® Simics Package Manager software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of Intel® Simics Package Manager software update to 1.8.3 or later.\r\nUpdates are available for download at this location:\xa0\r\nhttps://lemcenter.intel.com/productDownload/?Product=256660e5-a404-4390-b436-f64324d94959', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Simics Package Manager Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01116', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01116.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank Mohamed amine saidani for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-26027', 'title': 'Uncontrolled search path for some Intel® Simics Package Manager software before version 1.8.3 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-28172
INTEL-SA-01117
Intel® Trace Analyzer and Collector Software Advisory
A potential security vulnerability in some Intel® Trace Analyzer and Collector software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.
MEDIUM
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01117.html
da98e47e16cf7895d529cf19f9ba4fa1f6f0b94c6ef50a0d4319e8e79a3b2620
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® Trace Analyzer and Collector software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of Intel® Trace Analyzer and Collector software update to 2022.1 or later.\r\nUpdates are available for download at this location:\r\nhttps://www.intel.com/content/www/us/en/developer/articles/tool/oneapi-standalone-components.html#trace', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Trace Analyzer and Collector Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01117', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01117.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank ycdxsb for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-28172', 'title': 'Uncontrolled search path for some Intel® Trace Analyzer and Collector software before version 2022.1 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-25939
INTEL-SA-01118
3rd Generation Intel® Xeon® Scalable Processor Advisory
A potential security vulnerability in some 3rd Generation Intel® Xeon® Scalable Processors may allow denial of service. Intel is releasing microcode updates to mitigate this potential vulnerability.
MEDIUM
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01118.html
f21ce4106ffc2f4c21469f3f7c7fe8372322fa336271730cc7050afd79d213e6
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some 3rd Generation Intel® Xeon® Scalable Processors may allow denial of service. Intel is releasing microcode updates to mitigate this potential vulnerability. ', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of 3rd Generation Intel® Xeon® Scalable Processors update to the latest microcode version provided by the system manufacturer that addresses these issues.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Hardware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Denial of Service', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': '3rd Generation Intel® Xeon® Scalable Processor Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01118', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01118.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['This issue was found internally by Intel employees. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-25939', 'title': 'Mirrored regions with different values in 3rd Generation Intel® Xeon® Scalable Processors may allow a privileged user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-28947
INTEL-SA-01121
Intel® Server Board S2600ST Family Firmware Advisory
A potential security vulnerability in some Intel® Server Board S2600ST Family firmware may allow escalation of privilege. Intel is releasing software pdates to mitigate this potential vulnerability.
HIGH
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01121.html
fba8648b041cd545ae1cb778d03840e25d6fb28bdc302ae31f7df811fc61ba21
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® Server Board S2600ST Family firmware may allow escalation of privilege. Intel is releasing software pdates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating Intel® Server Board S2600ST Family firmware to version 02.01.0017 or later.\xa0\r\nUpdates are available for download at this location:\xa0\r\nhttps://www.intel.com/content/www/us/en/download/19139', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Server Board S2600ST Family Firmware Advisory ', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01121', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01121.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank Eason and vul_pwner for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-28947', 'title': 'Improper input validation in kernel mode driver for some Intel® Server Board S2600ST Family firmware before version 02.01.0017 may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7.1, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-29015
INTEL-SA-01122
Intel® VTune™ Profiler Software Advisory
A potential security vulnerability in some Intel® VTune™ Profiler software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.
MEDIUM
2024-08-13 03:00:00+03:00
2024-08-13 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01122.html
c44dc3ceb525c877cbb44ddf11b91249eb4502a4eaa32b43a59f6b38908f527a
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® VTune™ Profiler software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel® recommends updating Intel® oneAPI Base Toolkits to version 2024.1 or laterUpdates are available for download at this location:\xa0https://www.intel.com/content/www/us/en/developer/tools/oneapi/base-toolkit-download.html\xa0\r\nIntel® recommends updating VTune Profiler to version VTune 2024.1 or later.\r\nUpdates are available for download at this location:\xa0https://www.intel.com/content/www/us/en/developer/articles/tool/oneapi-standalone-components.html#vtune', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® VTune™ Profiler Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01122', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01122.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank ycdxsb for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-29015', 'title': 'Uncontrolled search path in some Intel® VTune™ Profiler software before versions 2024.1 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-31153
INTEL-SA-01124
Intel® QuickAssist Technology Software Advisory
A potential security vulnerabilities in some Intel® QuickAssist Technology software may allow escalation of privilege, denial of service or information disclosure. Intel is releasing software updates to mitigate this potential vulnerability.
MEDIUM
2025-02-11 03:00:00+03:00
2025-02-11 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01124.html
5bbbe1449ff537cfffbae6c2d1598aa28a09877090cae2f04a754172da05dfeb
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerabilities in some Intel® QuickAssist Technology software may allow escalation of privilege, denial of service or information disclosure. Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating Intel® QuickAssist Technology to version 2.2.0 or later.\xa0\r\nhttps://www.intel.com/content/www/us/en/download/765502/intel-quickassist-technology-driver-for-windows-hw-version-2-0.html', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® QuickAssist Technology Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01124', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2025-02-11T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2025-02-11T00:00:00+00:00', 'initial_release_date': '2025-02-11T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01124.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Copyright © Intel Corporation All rights reserved.'}, 'acknowledgments': [{'names': ['Intel would like to thank Aobo Wang of Chaitin Security Research Lab (CVE-2024-31858,CVE-2023-32277,CVE-2024-31153), ycdxsb (CVE-2024-29223), for reporting these issues. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-31153', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'title': 'Improper input validation for some Intel® QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.1, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N', 'userInteraction': 'PASSIVE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'NONE', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'HIGH', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'NONE'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-29223', 'cwe': {'id': 'CWE-427', 'name': 'Uncontrolled Search Path Element'}, 'title': 'Uncontrolled search path for some Intel® QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.7, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'HIGH', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'userInteraction': 'ACTIVE', 'attackComplexity': 'HIGH', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'HIGH', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-32277', 'cwe': {'id': 'CWE-822', 'name': 'Untrusted Pointer Dereference'}, 'title': 'Untrusted Pointer Dereference in I/O subsystem for some Intel® QAT software before version 2.0.5 may allow authenticated user to potentially enable information disclosure via local operating system access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.1, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 4.3, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N', 'userInteraction': 'PASSIVE', 'attackComplexity': 'LOW', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'NONE', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'LOW', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-31858', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'title': 'Out-of-bounds write for some Intel® QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7.3, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'HIGH', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2024-29223
INTEL-SA-01124
Intel® QuickAssist Technology Software Advisory
A potential security vulnerabilities in some Intel® QuickAssist Technology software may allow escalation of privilege, denial of service or information disclosure. Intel is releasing software updates to mitigate this potential vulnerability.
MEDIUM
2025-02-11 03:00:00+03:00
2025-02-11 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01124.html
74e2c8df9cfda35725b0c0c0e93f08e1aafd01414ae8bb6657ae8e6feaf7cc55
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerabilities in some Intel® QuickAssist Technology software may allow escalation of privilege, denial of service or information disclosure. Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating Intel® QuickAssist Technology to version 2.2.0 or later.\xa0\r\nhttps://www.intel.com/content/www/us/en/download/765502/intel-quickassist-technology-driver-for-windows-hw-version-2-0.html', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® QuickAssist Technology Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01124', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2025-02-11T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2025-02-11T00:00:00+00:00', 'initial_release_date': '2025-02-11T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01124.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Copyright © Intel Corporation All rights reserved.'}, 'acknowledgments': [{'names': ['Intel would like to thank Aobo Wang of Chaitin Security Research Lab (CVE-2024-31858,CVE-2023-32277,CVE-2024-31153), ycdxsb (CVE-2024-29223), for reporting these issues. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-31153', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'title': 'Improper input validation for some Intel® QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.1, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N', 'userInteraction': 'PASSIVE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'NONE', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'HIGH', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'NONE'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-29223', 'cwe': {'id': 'CWE-427', 'name': 'Uncontrolled Search Path Element'}, 'title': 'Uncontrolled search path for some Intel® QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.7, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'HIGH', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'userInteraction': 'ACTIVE', 'attackComplexity': 'HIGH', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'HIGH', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-32277', 'cwe': {'id': 'CWE-822', 'name': 'Untrusted Pointer Dereference'}, 'title': 'Untrusted Pointer Dereference in I/O subsystem for some Intel® QAT software before version 2.0.5 may allow authenticated user to potentially enable information disclosure via local operating system access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.1, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 4.3, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N', 'userInteraction': 'PASSIVE', 'attackComplexity': 'LOW', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'NONE', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'LOW', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-31858', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'title': 'Out-of-bounds write for some Intel® QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7.3, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'HIGH', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}
CVE-2023-32277
INTEL-SA-01124
Intel® QuickAssist Technology Software Advisory
A potential security vulnerabilities in some Intel® QuickAssist Technology software may allow escalation of privilege, denial of service or information disclosure. Intel is releasing software updates to mitigate this potential vulnerability.
MEDIUM
2025-02-11 03:00:00+03:00
2025-02-11 03:00:00+03:00
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01124.html
94bc0c3f0eb7381386b3d00d53e04fb8bb6e5aa0e7b27d7768095cee8c7d1426
2026-05-29 08:17:14.865208+03:00
2026-06-25 11:41:12.780439+03:00
{'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerabilities in some Intel® QuickAssist Technology software may allow escalation of privilege, denial of service or information disclosure. Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating Intel® QuickAssist Technology to version 2.2.0 or later.\xa0\r\nhttps://www.intel.com/content/www/us/en/download/765502/intel-quickassist-technology-driver-for-windows-hw-version-2-0.html', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® QuickAssist Technology Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01124', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2025-02-11T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2025-02-11T00:00:00+00:00', 'initial_release_date': '2025-02-11T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01124.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Copyright © Intel Corporation All rights reserved.'}, 'acknowledgments': [{'names': ['Intel would like to thank Aobo Wang of Chaitin Security Research Lab (CVE-2024-31858,CVE-2023-32277,CVE-2024-31153), ycdxsb (CVE-2024-29223), for reporting these issues. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-31153', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'title': 'Improper input validation for some Intel® QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.1, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N', 'userInteraction': 'PASSIVE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'NONE', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'HIGH', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'NONE'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-29223', 'cwe': {'id': 'CWE-427', 'name': 'Uncontrolled Search Path Element'}, 'title': 'Uncontrolled search path for some Intel® QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.7, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'HIGH', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'userInteraction': 'ACTIVE', 'attackComplexity': 'HIGH', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'HIGH', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-32277', 'cwe': {'id': 'CWE-822', 'name': 'Untrusted Pointer Dereference'}, 'title': 'Untrusted Pointer Dereference in I/O subsystem for some Intel® QAT software before version 2.0.5 may allow authenticated user to potentially enable information disclosure via local operating system access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.1, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 4.3, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N', 'userInteraction': 'PASSIVE', 'attackComplexity': 'LOW', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'NONE', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'LOW', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-31858', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'title': 'Out-of-bounds write for some Intel® QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7.3, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'HIGH', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]}