Zeros312
CVE-2024-25571 | INTEL-SA-01120 | Intel® SPS Firmware Advisory | A potential security vulnerability in some Intel® Server Platform Services (Intel® SPS) firmware may allow denial of service. Intel is releasing firmware updates to mitigate this potential vulnerability. | LOW | 2025-02-11 03:00:00+03:00 | 2025-02-11 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01120.html | 3f53b24ef18b4ca0e0ef3ab465f08c9de01914b5897e420da527b8440b9d7245 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® Server Platform Services (Intel® SPS) firmware may allow denial of service. Intel is releasing firmware updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of Intel® SPS update to the latest version provided by the system manufacturer that addresses these issues.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Low', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Denial of Service', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® SPS Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01120', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2025-02-11T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2025-02-11T00:00:00+00:00', 'initial_release_date': '2025-02-11T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01120.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Copyright © Intel Corporation All rights reserved.'}, 'acknowledgments': [{'names': ['This issue was found internally by Intel employees.\xa0 Intel would like to thank Tomasz Bagniuk, Bartosz Górski, and Piotr Dorożyński. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-25571', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'title': 'Improper input validation in some Intel® SPS firmware before SPS_E5_06.01.04.059.0 may allow a privileged user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 2.3, 'attackVector': 'LOCAL', 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'HIGH', 'confidentialityImpact': 'NONE'}, 'cvss_v4': {'version': '4.0', 'baseScore': 4.6, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'HIGH', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'NONE', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'LOW', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'NONE'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-21807 | INTEL-SA-00918 | Intel® Ethernet Controllers and Adapters Advisory | Potential security vulnerabilities in some Intel® Ethernet Controllers and Adapters may allow escalation of privilege or denial of service. Intel is releasing firmware and software updates to mitigate these potential vulnerabilities. | HIGH | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00918.html | 85c2bf7afb1ed3a34edb4603d452cb6e4ce074fd75bc395f6ab8479f5c37d620 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® Ethernet Controllers and Adapters may allow escalation of privilege or denial of service. Intel is releasing firmware and software updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating the software for impacted Intel® Ethernet Controllers and Adapters to the versions provided below or later.\r\n\xa0\r\nUpdate to Intel® Ethernet Complete Driver Pack versions 28.3 or later.\r\nIntel® Ethernet Controllers E800 Series with NVM image versions 4.4 or higher included with Intel® Ethernet Adapter Complete Driver Pack versions 28.3 or higher.\xa0\r\nIntel recommends updating the firmware for impacted Intel® Ethernet Controllers and Adapters to the versions provided below or later.\r\nUpdate firmware to NIC1.3 PV, NVM image version 3.36 or higher included Intel(R) Ethernet Complete Driver Pack versions 28.3 or later.\r\nUpdates are available for download at this location:\xa0\xa0Intel® Ethernet Adapter Complete Driver Pack', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware,software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Ethernet Controllers and Adapters Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-00918', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00918.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['The following issues were found internally by Intel employees: CVE-2024-23981, CVE-2024-21810, CVE-2024-21807, CVE-2024-23497, CVE-and 2024-24986. Intel would like to thank Daniel Medina Velazquez and Thierry Fernandes Faria.\xa0\r\nThe following issues were found internally by Intel employees: CVE-2024-21806, CVE-2024-23499 and CVE-2024-24983.\xa0\r\nIntel would like to thank mohammed for reporting CVE-2024-21769. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-21810', 'title': 'Improper input validation in the Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23497', 'title': 'Out-of-bounds write in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-24983', 'title': 'Protection mechanism failure in firmware for some Intel® Ethernet Network Controllers and Adapters E810 Series before version 4.4 may allow an unauthenticated user to potentially enable denial of service via network access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21807', 'title': 'Improper initialization in the Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23981', 'title': 'Wrap-around error in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23499', 'title': 'Protection mechanism failure in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters E810 Series before version 28.3 may allow an unauthenticated user to potentially enable denial of service via network access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21769', 'title': ' Uncontrolled search path in some Intel® Ethernet Connection I219-LM install software may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-24986', 'title': 'Improper access control in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21806', 'title': 'Improper conditions check in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters E810 Series before version 28.3 may allow an authenticated user to potentially enable denial of service via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-23981 | INTEL-SA-00918 | Intel® Ethernet Controllers and Adapters Advisory | Potential security vulnerabilities in some Intel® Ethernet Controllers and Adapters may allow escalation of privilege or denial of service. Intel is releasing firmware and software updates to mitigate these potential vulnerabilities. | HIGH | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00918.html | 25eda300d74f221d61540265eadd81ca43641540b5ecd985c3ef5d7f3807faa0 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® Ethernet Controllers and Adapters may allow escalation of privilege or denial of service. Intel is releasing firmware and software updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating the software for impacted Intel® Ethernet Controllers and Adapters to the versions provided below or later.\r\n\xa0\r\nUpdate to Intel® Ethernet Complete Driver Pack versions 28.3 or later.\r\nIntel® Ethernet Controllers E800 Series with NVM image versions 4.4 or higher included with Intel® Ethernet Adapter Complete Driver Pack versions 28.3 or higher.\xa0\r\nIntel recommends updating the firmware for impacted Intel® Ethernet Controllers and Adapters to the versions provided below or later.\r\nUpdate firmware to NIC1.3 PV, NVM image version 3.36 or higher included Intel(R) Ethernet Complete Driver Pack versions 28.3 or later.\r\nUpdates are available for download at this location:\xa0\xa0Intel® Ethernet Adapter Complete Driver Pack', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware,software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Ethernet Controllers and Adapters Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-00918', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00918.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['The following issues were found internally by Intel employees: CVE-2024-23981, CVE-2024-21810, CVE-2024-21807, CVE-2024-23497, CVE-and 2024-24986. Intel would like to thank Daniel Medina Velazquez and Thierry Fernandes Faria.\xa0\r\nThe following issues were found internally by Intel employees: CVE-2024-21806, CVE-2024-23499 and CVE-2024-24983.\xa0\r\nIntel would like to thank mohammed for reporting CVE-2024-21769. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-21810', 'title': 'Improper input validation in the Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23497', 'title': 'Out-of-bounds write in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-24983', 'title': 'Protection mechanism failure in firmware for some Intel® Ethernet Network Controllers and Adapters E810 Series before version 4.4 may allow an unauthenticated user to potentially enable denial of service via network access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21807', 'title': 'Improper initialization in the Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23981', 'title': 'Wrap-around error in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23499', 'title': 'Protection mechanism failure in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters E810 Series before version 28.3 may allow an unauthenticated user to potentially enable denial of service via network access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21769', 'title': ' Uncontrolled search path in some Intel® Ethernet Connection I219-LM install software may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-24986', 'title': 'Improper access control in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21806', 'title': 'Improper conditions check in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters E810 Series before version 28.3 may allow an authenticated user to potentially enable denial of service via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-28036 | INTEL-SA-01252 | Intel® Arc™ GPU Advisory | A potential security vulnerability in some Intel® Arc™ GPU may allow denial of service. Intel is releasing software updates to mitigate this potential vulnerability. | MEDIUM | 2025-05-13 03:00:00+03:00 | 2025-05-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01252.html | 459d78d18ea7da45411c1ab77f0ff78a729d4ba133e86776851a16ef5d98b5bd | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® Arc™ GPU may allow denial of service. Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating Intel® Arc™ A-series graphics software to version 31.0.101.3277 or later.Updates are available for download at this location:https://www.intel.com/content/www/us/en/download/785597\r\n\xa0\r\nIntel recommends updating Intel® Arc™ Pro A-series graphics software to version 30.0.101.1729 or later.Updates are available for download at this location:https://www.intel.com/content/www/us/en/download/741626', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Hardware,software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Denial of Service', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Arc™ GPU Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01252', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2025-05-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2025-05-13T00:00:00+00:00', 'initial_release_date': '2025-05-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01252.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Copyright © Intel Corporation All rights reserved.'}, 'acknowledgments': [{'names': ['This issue was found internally by Intel employees. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-28036', 'cwe': {'id': 'CWE-754', 'name': 'Improper conditions check'}, 'title': 'Improper conditions check for some Intel® Arc™ GPU may allow an authenticated user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 5.6, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.7, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'attackRequirements': 'NONE', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'NONE', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'HIGH', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'NONE'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2025-20079 | INTEL-SA-01263 | Intel® Advisor Software Advisory | Potential security vulnerability for some Intel® Advisor software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability. | MEDIUM | 2025-05-13 03:00:00+03:00 | 2025-05-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01263.html | c1976a0f5d1b5ca5b2b306b81e0c3cef9486f167b4e94790c4d20b9b7e8d77b2 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerability for some Intel® Advisor software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating Intel® Advisor standalone component software software to version 2024.2 or later.\xa0\xa0\r\nUpdates are available for download at this location:\r\nhttps://www.intel.com/content/www/us/en/developer/tools/oneapi/advisor.html\r\n\xa0\r\nIntel recommends updating Intel® oneAPI Base Toolkit to 2024.2 or later.\r\nUpdates are available for download at this location:\r\nhttps://www.intel.com/content/www/us/en/developer/tools/oneapi/base-toolkit.html', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Advisor Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01263', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2025-05-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2025-05-13T00:00:00+00:00', 'initial_release_date': '2025-05-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01263.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Copyright © Intel Corporation All rights reserved.'}, 'acknowledgments': [{'names': ['Intel would like to thank ycdxsb for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2025-20079', 'cwe': {'id': 'CWE-427', 'name': 'Uncontrolled search path'}, 'title': 'Uncontrolled search path for some Intel® Advisor software may allow an authenticated user to potentially enable escalation of privilege via local access.\r\n', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.7, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'HIGH', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'userInteraction': 'ACTIVE', 'attackComplexity': 'HIGH', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'HIGH', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2025-21093 | INTEL-SA-01321 | Intel® Driver & Support Assistant Tool Advisory | A potential security vulnerability for some Intel® Driver & Support Assistant Tool software may allow escalation of privilege, Intel is releasing software updates to mitigate this potential vulnerability. | MEDIUM | 2025-08-12 03:00:00+03:00 | 2025-08-12 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01321.html | 305357e5e628e9749b90f5f40687a3dd036313d47f93280e826f00dd20f9d79a | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability for some Intel® Driver & Support Assistant Tool software may allow escalation of privilege, Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating the Intel® Driver & Support Assistant Tool software to version 24.6.49.8 or later.\r\nUpdates are available for download at this location:https://www.intel.com/content/www/us/en/support/detect.html', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Driver & Support Assistant Tool Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01321', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2025-08-12T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2025-08-12T00:00:00+00:00', 'initial_release_date': '2025-08-12T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01321.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Copyright © Intel Corporation All rights reserved.'}, 'acknowledgments': [{'names': ['Intel would like to thank FalconCorruption for reporting these issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2025-21093', 'cwe': {'id': 'CWE-427', 'name': 'Uncontrolled search path'}, 'title': 'Uncontrolled search path element for some Intel® Driver & Support Assistant Tool software before version 24.6.49.8 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.7, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'HIGH', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'userInteraction': 'PASSIVE', 'attackComplexity': 'HIGH', 'attackRequirements': 'NONE', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'HIGH', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-23499 | INTEL-SA-00918 | Intel® Ethernet Controllers and Adapters Advisory | Potential security vulnerabilities in some Intel® Ethernet Controllers and Adapters may allow escalation of privilege or denial of service. Intel is releasing firmware and software updates to mitigate these potential vulnerabilities. | HIGH | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00918.html | 6b4a9ce24fdfd28a9652b79a459e83dcf9e7137a5da7fde1fe2cf141bbadcaca | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® Ethernet Controllers and Adapters may allow escalation of privilege or denial of service. Intel is releasing firmware and software updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating the software for impacted Intel® Ethernet Controllers and Adapters to the versions provided below or later.\r\n\xa0\r\nUpdate to Intel® Ethernet Complete Driver Pack versions 28.3 or later.\r\nIntel® Ethernet Controllers E800 Series with NVM image versions 4.4 or higher included with Intel® Ethernet Adapter Complete Driver Pack versions 28.3 or higher.\xa0\r\nIntel recommends updating the firmware for impacted Intel® Ethernet Controllers and Adapters to the versions provided below or later.\r\nUpdate firmware to NIC1.3 PV, NVM image version 3.36 or higher included Intel(R) Ethernet Complete Driver Pack versions 28.3 or later.\r\nUpdates are available for download at this location:\xa0\xa0Intel® Ethernet Adapter Complete Driver Pack', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware,software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Ethernet Controllers and Adapters Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-00918', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00918.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['The following issues were found internally by Intel employees: CVE-2024-23981, CVE-2024-21810, CVE-2024-21807, CVE-2024-23497, CVE-and 2024-24986. Intel would like to thank Daniel Medina Velazquez and Thierry Fernandes Faria.\xa0\r\nThe following issues were found internally by Intel employees: CVE-2024-21806, CVE-2024-23499 and CVE-2024-24983.\xa0\r\nIntel would like to thank mohammed for reporting CVE-2024-21769. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-21810', 'title': 'Improper input validation in the Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23497', 'title': 'Out-of-bounds write in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-24983', 'title': 'Protection mechanism failure in firmware for some Intel® Ethernet Network Controllers and Adapters E810 Series before version 4.4 may allow an unauthenticated user to potentially enable denial of service via network access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21807', 'title': 'Improper initialization in the Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23981', 'title': 'Wrap-around error in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23499', 'title': 'Protection mechanism failure in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters E810 Series before version 28.3 may allow an unauthenticated user to potentially enable denial of service via network access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21769', 'title': ' Uncontrolled search path in some Intel® Ethernet Connection I219-LM install software may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-24986', 'title': 'Improper access control in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21806', 'title': 'Improper conditions check in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters E810 Series before version 28.3 may allow an authenticated user to potentially enable denial of service via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-21769 | INTEL-SA-00918 | Intel® Ethernet Controllers and Adapters Advisory | Potential security vulnerabilities in some Intel® Ethernet Controllers and Adapters may allow escalation of privilege or denial of service. Intel is releasing firmware and software updates to mitigate these potential vulnerabilities. | HIGH | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00918.html | d0d75d152b9dc1fb2e88add37fe6359b37709185c3c80423c01685ce9aadf3bf | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® Ethernet Controllers and Adapters may allow escalation of privilege or denial of service. Intel is releasing firmware and software updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating the software for impacted Intel® Ethernet Controllers and Adapters to the versions provided below or later.\r\n\xa0\r\nUpdate to Intel® Ethernet Complete Driver Pack versions 28.3 or later.\r\nIntel® Ethernet Controllers E800 Series with NVM image versions 4.4 or higher included with Intel® Ethernet Adapter Complete Driver Pack versions 28.3 or higher.\xa0\r\nIntel recommends updating the firmware for impacted Intel® Ethernet Controllers and Adapters to the versions provided below or later.\r\nUpdate firmware to NIC1.3 PV, NVM image version 3.36 or higher included Intel(R) Ethernet Complete Driver Pack versions 28.3 or later.\r\nUpdates are available for download at this location:\xa0\xa0Intel® Ethernet Adapter Complete Driver Pack', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware,software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Ethernet Controllers and Adapters Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-00918', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00918.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['The following issues were found internally by Intel employees: CVE-2024-23981, CVE-2024-21810, CVE-2024-21807, CVE-2024-23497, CVE-and 2024-24986. Intel would like to thank Daniel Medina Velazquez and Thierry Fernandes Faria.\xa0\r\nThe following issues were found internally by Intel employees: CVE-2024-21806, CVE-2024-23499 and CVE-2024-24983.\xa0\r\nIntel would like to thank mohammed for reporting CVE-2024-21769. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-21810', 'title': 'Improper input validation in the Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23497', 'title': 'Out-of-bounds write in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-24983', 'title': 'Protection mechanism failure in firmware for some Intel® Ethernet Network Controllers and Adapters E810 Series before version 4.4 may allow an unauthenticated user to potentially enable denial of service via network access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21807', 'title': 'Improper initialization in the Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23981', 'title': 'Wrap-around error in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23499', 'title': 'Protection mechanism failure in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters E810 Series before version 28.3 may allow an unauthenticated user to potentially enable denial of service via network access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21769', 'title': ' Uncontrolled search path in some Intel® Ethernet Connection I219-LM install software may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-24986', 'title': 'Improper access control in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21806', 'title': 'Improper conditions check in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters E810 Series before version 28.3 may allow an authenticated user to potentially enable denial of service via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-24986 | INTEL-SA-00918 | Intel® Ethernet Controllers and Adapters Advisory | Potential security vulnerabilities in some Intel® Ethernet Controllers and Adapters may allow escalation of privilege or denial of service. Intel is releasing firmware and software updates to mitigate these potential vulnerabilities. | HIGH | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00918.html | 488b0bc081134ed473df47a7a82822f40940eb3eb2426c3ee7e70a1f30ea9db3 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® Ethernet Controllers and Adapters may allow escalation of privilege or denial of service. Intel is releasing firmware and software updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating the software for impacted Intel® Ethernet Controllers and Adapters to the versions provided below or later.\r\n\xa0\r\nUpdate to Intel® Ethernet Complete Driver Pack versions 28.3 or later.\r\nIntel® Ethernet Controllers E800 Series with NVM image versions 4.4 or higher included with Intel® Ethernet Adapter Complete Driver Pack versions 28.3 or higher.\xa0\r\nIntel recommends updating the firmware for impacted Intel® Ethernet Controllers and Adapters to the versions provided below or later.\r\nUpdate firmware to NIC1.3 PV, NVM image version 3.36 or higher included Intel(R) Ethernet Complete Driver Pack versions 28.3 or later.\r\nUpdates are available for download at this location:\xa0\xa0Intel® Ethernet Adapter Complete Driver Pack', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware,software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Ethernet Controllers and Adapters Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-00918', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00918.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['The following issues were found internally by Intel employees: CVE-2024-23981, CVE-2024-21810, CVE-2024-21807, CVE-2024-23497, CVE-and 2024-24986. Intel would like to thank Daniel Medina Velazquez and Thierry Fernandes Faria.\xa0\r\nThe following issues were found internally by Intel employees: CVE-2024-21806, CVE-2024-23499 and CVE-2024-24983.\xa0\r\nIntel would like to thank mohammed for reporting CVE-2024-21769. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-21810', 'title': 'Improper input validation in the Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23497', 'title': 'Out-of-bounds write in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-24983', 'title': 'Protection mechanism failure in firmware for some Intel® Ethernet Network Controllers and Adapters E810 Series before version 4.4 may allow an unauthenticated user to potentially enable denial of service via network access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21807', 'title': 'Improper initialization in the Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23981', 'title': 'Wrap-around error in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23499', 'title': 'Protection mechanism failure in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters E810 Series before version 28.3 may allow an unauthenticated user to potentially enable denial of service via network access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21769', 'title': ' Uncontrolled search path in some Intel® Ethernet Connection I219-LM install software may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-24986', 'title': 'Improper access control in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21806', 'title': 'Improper conditions check in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters E810 Series before version 28.3 may allow an authenticated user to potentially enable denial of service via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-21806 | INTEL-SA-00918 | Intel® Ethernet Controllers and Adapters Advisory | Potential security vulnerabilities in some Intel® Ethernet Controllers and Adapters may allow escalation of privilege or denial of service. Intel is releasing firmware and software updates to mitigate these potential vulnerabilities. | HIGH | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00918.html | 6fa993532c299ed80d7606758382456d337c2fea9f8221acb31ecdc03d3349d7 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® Ethernet Controllers and Adapters may allow escalation of privilege or denial of service. Intel is releasing firmware and software updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating the software for impacted Intel® Ethernet Controllers and Adapters to the versions provided below or later.\r\n\xa0\r\nUpdate to Intel® Ethernet Complete Driver Pack versions 28.3 or later.\r\nIntel® Ethernet Controllers E800 Series with NVM image versions 4.4 or higher included with Intel® Ethernet Adapter Complete Driver Pack versions 28.3 or higher.\xa0\r\nIntel recommends updating the firmware for impacted Intel® Ethernet Controllers and Adapters to the versions provided below or later.\r\nUpdate firmware to NIC1.3 PV, NVM image version 3.36 or higher included Intel(R) Ethernet Complete Driver Pack versions 28.3 or later.\r\nUpdates are available for download at this location:\xa0\xa0Intel® Ethernet Adapter Complete Driver Pack', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware,software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Ethernet Controllers and Adapters Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-00918', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00918.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['The following issues were found internally by Intel employees: CVE-2024-23981, CVE-2024-21810, CVE-2024-21807, CVE-2024-23497, CVE-and 2024-24986. Intel would like to thank Daniel Medina Velazquez and Thierry Fernandes Faria.\xa0\r\nThe following issues were found internally by Intel employees: CVE-2024-21806, CVE-2024-23499 and CVE-2024-24983.\xa0\r\nIntel would like to thank mohammed for reporting CVE-2024-21769. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-21810', 'title': 'Improper input validation in the Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23497', 'title': 'Out-of-bounds write in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-24983', 'title': 'Protection mechanism failure in firmware for some Intel® Ethernet Network Controllers and Adapters E810 Series before version 4.4 may allow an unauthenticated user to potentially enable denial of service via network access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21807', 'title': 'Improper initialization in the Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23981', 'title': 'Wrap-around error in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23499', 'title': 'Protection mechanism failure in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters E810 Series before version 28.3 may allow an unauthenticated user to potentially enable denial of service via network access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21769', 'title': ' Uncontrolled search path in some Intel® Ethernet Connection I219-LM install software may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-24986', 'title': 'Improper access control in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21806', 'title': 'Improper conditions check in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters E810 Series before version 28.3 may allow an authenticated user to potentially enable denial of service via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2021-37577 | INTEL-SA-00606 | Intel® Wireless Bluetooth® and Killer™ Bluetooth® Advisory | A potential security vulnerability in some Intel® Wireless Bluetooth® and Killer™ Bluetooth® products may allow escalation of privilege. Intel is releasing firmware updates to mitigate this potential vulnerability. | MEDIUM | 2025-02-11 03:00:00+03:00 | 2025-02-11 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00606.html | 0d0dc10e5ba86274b2ff1a8e981409a4da6fc7b3d36d9fdf415ab209cdd3894f | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® Wireless Bluetooth® and Killer™ Bluetooth® products may allow escalation of privilege. Intel is releasing firmware updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating the affected Intel® Wireless Bluetooth® and Killer™ Bluetooth® products to version 22.100 or later.\r\nWindows 10 and Windows 11 updates are available for download at this location:\r\nhttps://www.intel.com/content/www/us/en/download/18649/intel-wireless-bluetooth-for-windows-10-and-windows-11.html\r\n\xa0\r\nFor the latest Linux updates refer to the links below:\r\nLinux software Driver: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/\r\nLinux firmware: link\r\nProduct Discontinuation Notice:\xa0\r\nIntel has issued a Product Discontinuation Notice for:\r\nIntel® Dual Band Wireless-AC 8265 and Intel® Dual Band Wireless-AC 8260 as of February 2023. The Intel® Dual Band Wireless-AC 8265 and Intel® Dual Band Wireless-AC 8260 are not supported with any additional functional, security, or other updates. Intel recommends that users discontinue use and migrate to the newer generation product listed in Recommendations as soon as possible.Intel® Dual Band Wireless-AC 3168, Intel® Wireless 7265 (Rev D) Family and Intel® Dual Band Wireless-AC 3165 as of April 2024. The Intel® Dual Band Wireless-AC 3168, Intel® Wireless 7265 (Rev D) Family and Intel® Dual Band Wireless-AC 3165 are not supported with any additional functional, security, or other updates. Intel recommends that users discontinue use and migrate to the newer generation product listed in Recommendations as soon as possible.\r\n\r\nReference Documentation:\r\nLinux* Support for Intel® Wireless Adapters: \xa0https://www.intel.com/content/www/us/en/support/articles/000005511/wireless.html', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Wireless Bluetooth® and Killer™ Bluetooth® Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-00606', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2025-02-11T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release.'}], 'current_release_date': '2025-02-11T00:00:00+00:00', 'initial_release_date': '2025-02-11T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00606.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Copyright © Intel Corporation All rights reserved.'}, 'acknowledgments': [{'names': ['This issue was found externally. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2021-37577', 'cwe': {'id': 'CWE-284', 'name': 'Improper Access Control'}, 'title': 'Improper access control in the firmware for some Intel® Wireless Bluetooth® and Killer™ Bluetooth® products before version 22.100 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 4.6, 'attackVector': 'ADJACENT_NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N', 'integrityImpact': 'LOW', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.3, 'attackVector': 'ADJACENT', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'NONE', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'LOW', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'NONE', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'LOW'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-21787 | INTEL-SA-00790 | BMRA Software Advisory | A potential security vulnerability in some Bare Metal Reference System Architecture (BMRA) software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability. | MEDIUM | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00790.html | 2275e246c0c4d68336894f7493250f9a35297e69c949062335f6d24ed7c5abeb | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Bare Metal Reference System Architecture (BMRA) software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of BMRA software update to 22.08 or later.\r\nUpdates are available for download at this location:\r\nhttps://github.com/intel/container-experience-kits/releases', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'BMRA Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-00790', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00790.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['This issue was\xa0found internally by Intel. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-21787', 'title': 'Inadequate encryption strength for some BMRA software before version 22.08 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7.1, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-21810 | INTEL-SA-00918 | Intel® Ethernet Controllers and Adapters Advisory | Potential security vulnerabilities in some Intel® Ethernet Controllers and Adapters may allow escalation of privilege or denial of service. Intel is releasing firmware and software updates to mitigate these potential vulnerabilities. | HIGH | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00918.html | b95964c102f510d624083fcad76298aea32102b9b551d648284cfef675ab8180 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® Ethernet Controllers and Adapters may allow escalation of privilege or denial of service. Intel is releasing firmware and software updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating the software for impacted Intel® Ethernet Controllers and Adapters to the versions provided below or later.\r\n\xa0\r\nUpdate to Intel® Ethernet Complete Driver Pack versions 28.3 or later.\r\nIntel® Ethernet Controllers E800 Series with NVM image versions 4.4 or higher included with Intel® Ethernet Adapter Complete Driver Pack versions 28.3 or higher.\xa0\r\nIntel recommends updating the firmware for impacted Intel® Ethernet Controllers and Adapters to the versions provided below or later.\r\nUpdate firmware to NIC1.3 PV, NVM image version 3.36 or higher included Intel(R) Ethernet Complete Driver Pack versions 28.3 or later.\r\nUpdates are available for download at this location:\xa0\xa0Intel® Ethernet Adapter Complete Driver Pack', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware,software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Ethernet Controllers and Adapters Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-00918', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00918.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['The following issues were found internally by Intel employees: CVE-2024-23981, CVE-2024-21810, CVE-2024-21807, CVE-2024-23497, CVE-and 2024-24986. Intel would like to thank Daniel Medina Velazquez and Thierry Fernandes Faria.\xa0\r\nThe following issues were found internally by Intel employees: CVE-2024-21806, CVE-2024-23499 and CVE-2024-24983.\xa0\r\nIntel would like to thank mohammed for reporting CVE-2024-21769. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-21810', 'title': 'Improper input validation in the Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23497', 'title': 'Out-of-bounds write in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-24983', 'title': 'Protection mechanism failure in firmware for some Intel® Ethernet Network Controllers and Adapters E810 Series before version 4.4 may allow an unauthenticated user to potentially enable denial of service via network access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21807', 'title': 'Improper initialization in the Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23981', 'title': 'Wrap-around error in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23499', 'title': 'Protection mechanism failure in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters E810 Series before version 28.3 may allow an unauthenticated user to potentially enable denial of service via network access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21769', 'title': ' Uncontrolled search path in some Intel® Ethernet Connection I219-LM install software may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-24986', 'title': 'Improper access control in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21806', 'title': 'Improper conditions check in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters E810 Series before version 28.3 may allow an authenticated user to potentially enable denial of service via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-23497 | INTEL-SA-00918 | Intel® Ethernet Controllers and Adapters Advisory | Potential security vulnerabilities in some Intel® Ethernet Controllers and Adapters may allow escalation of privilege or denial of service. Intel is releasing firmware and software updates to mitigate these potential vulnerabilities. | HIGH | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00918.html | 19734a682a497a67d086cb5acd6e4dfea2dd7296c35d2c8f068bfef369859d25 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® Ethernet Controllers and Adapters may allow escalation of privilege or denial of service. Intel is releasing firmware and software updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating the software for impacted Intel® Ethernet Controllers and Adapters to the versions provided below or later.\r\n\xa0\r\nUpdate to Intel® Ethernet Complete Driver Pack versions 28.3 or later.\r\nIntel® Ethernet Controllers E800 Series with NVM image versions 4.4 or higher included with Intel® Ethernet Adapter Complete Driver Pack versions 28.3 or higher.\xa0\r\nIntel recommends updating the firmware for impacted Intel® Ethernet Controllers and Adapters to the versions provided below or later.\r\nUpdate firmware to NIC1.3 PV, NVM image version 3.36 or higher included Intel(R) Ethernet Complete Driver Pack versions 28.3 or later.\r\nUpdates are available for download at this location:\xa0\xa0Intel® Ethernet Adapter Complete Driver Pack', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware,software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Ethernet Controllers and Adapters Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-00918', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00918.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['The following issues were found internally by Intel employees: CVE-2024-23981, CVE-2024-21810, CVE-2024-21807, CVE-2024-23497, CVE-and 2024-24986. Intel would like to thank Daniel Medina Velazquez and Thierry Fernandes Faria.\xa0\r\nThe following issues were found internally by Intel employees: CVE-2024-21806, CVE-2024-23499 and CVE-2024-24983.\xa0\r\nIntel would like to thank mohammed for reporting CVE-2024-21769. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-21810', 'title': 'Improper input validation in the Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23497', 'title': 'Out-of-bounds write in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-24983', 'title': 'Protection mechanism failure in firmware for some Intel® Ethernet Network Controllers and Adapters E810 Series before version 4.4 may allow an unauthenticated user to potentially enable denial of service via network access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21807', 'title': 'Improper initialization in the Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23981', 'title': 'Wrap-around error in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23499', 'title': 'Protection mechanism failure in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters E810 Series before version 28.3 may allow an unauthenticated user to potentially enable denial of service via network access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21769', 'title': ' Uncontrolled search path in some Intel® Ethernet Connection I219-LM install software may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-24986', 'title': 'Improper access control in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21806', 'title': 'Improper conditions check in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters E810 Series before version 28.3 may allow an authenticated user to potentially enable denial of service via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-24983 | INTEL-SA-00918 | Intel® Ethernet Controllers and Adapters Advisory | Potential security vulnerabilities in some Intel® Ethernet Controllers and Adapters may allow escalation of privilege or denial of service. Intel is releasing firmware and software updates to mitigate these potential vulnerabilities. | HIGH | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00918.html | b6642cc94b65a15687a4ffe6b91de8d622cc0eb04463b293baa4bfa9fae1551b | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® Ethernet Controllers and Adapters may allow escalation of privilege or denial of service. Intel is releasing firmware and software updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating the software for impacted Intel® Ethernet Controllers and Adapters to the versions provided below or later.\r\n\xa0\r\nUpdate to Intel® Ethernet Complete Driver Pack versions 28.3 or later.\r\nIntel® Ethernet Controllers E800 Series with NVM image versions 4.4 or higher included with Intel® Ethernet Adapter Complete Driver Pack versions 28.3 or higher.\xa0\r\nIntel recommends updating the firmware for impacted Intel® Ethernet Controllers and Adapters to the versions provided below or later.\r\nUpdate firmware to NIC1.3 PV, NVM image version 3.36 or higher included Intel(R) Ethernet Complete Driver Pack versions 28.3 or later.\r\nUpdates are available for download at this location:\xa0\xa0Intel® Ethernet Adapter Complete Driver Pack', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware,software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Ethernet Controllers and Adapters Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-00918', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00918.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['The following issues were found internally by Intel employees: CVE-2024-23981, CVE-2024-21810, CVE-2024-21807, CVE-2024-23497, CVE-and 2024-24986. Intel would like to thank Daniel Medina Velazquez and Thierry Fernandes Faria.\xa0\r\nThe following issues were found internally by Intel employees: CVE-2024-21806, CVE-2024-23499 and CVE-2024-24983.\xa0\r\nIntel would like to thank mohammed for reporting CVE-2024-21769. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-21810', 'title': 'Improper input validation in the Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23497', 'title': 'Out-of-bounds write in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-24983', 'title': 'Protection mechanism failure in firmware for some Intel® Ethernet Network Controllers and Adapters E810 Series before version 4.4 may allow an unauthenticated user to potentially enable denial of service via network access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21807', 'title': 'Improper initialization in the Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23981', 'title': 'Wrap-around error in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23499', 'title': 'Protection mechanism failure in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters E810 Series before version 28.3 may allow an unauthenticated user to potentially enable denial of service via network access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21769', 'title': ' Uncontrolled search path in some Intel® Ethernet Connection I219-LM install software may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-24986', 'title': 'Improper access control in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21806', 'title': 'Improper conditions check in Linux kernel mode driver for some Intel® Ethernet Network Controllers and Adapters E810 Series before version 28.3 may allow an authenticated user to potentially enable denial of service via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2025-20097 | INTEL-SA-00990 | Intel® Server Board BMC Firmware Advisory | Potential security vulnerabilities in some Intel® Server Board BMC Firmware may allow escalation of privilege, information disclosure or denial of service. Intel is releasing firmware updates to mitigate these potential vulnerabilities.
| MEDIUM | 2025-02-11 03:00:00+03:00 | 2025-02-11 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00990.html | 8a5b4a9ea6d887dd051e150eda777cb06ed6c9debdf91547292cf9b34b603e9c | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® Server Board BMC Firmware may allow escalation of privilege, information disclosure or denial of service. Intel is releasing firmware updates to mitigate these potential vulnerabilities.\r\n', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Updates for Intel® Server Board S2600WF Family can be found here.\r\nUpdates for Intel® Server Board S2600ST Family can be found here.\r\nUpdates for Intel® Server Board S2600BP Family can be found here. \xa0\r\nUpdates for Intel® Server Board M70KLP Family BMC Firmware can be found\xa0here.\r\nUpdates for Intel® Server M20NTP Family BMC Firmware can be found\xa0here.\r\nUpdates for Intel® Server Board M10JNP Family BMC Firmware can be found\xa0here.\xa0\r\nUpdates for Intel® Server Board M50CYP Family can be found here.\r\nUpdates for Intel® Server Board D50TNP Family can be found here.\xa0\r\nUpdates for Intel® Server M50FCP Family can be found here.\r\nUpdates for Intel® Server Board D50DNP Family can be found here.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Critical', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Server Board BMC Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-00990', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2025-02-11T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2025-02-11T00:00:00+00:00', 'initial_release_date': '2025-02-11T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00990.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Copyright © Intel Corporation All rights reserved.'}, 'acknowledgments': [{'names': ['CVE-2023-25191, CVE-2023-25192 were found internally by Intel employees. Intel would like to thank Alex Gutkin and Ignacio Hernandez.\xa0\r\nCVE-2023-31276 was found internally by Intel employees. Intel would like to thank Daniel Medina Velazquez and Thierry Fernandes Faria.\xa0\r\nCVE-2023-29164 was found internally by Intel employees. Intel would like to thank Tal Rosen, Benny Zeltser and Rami Sudai. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2025-20097', 'cwe': {'id': 'CWE-703', 'name': 'Improper Check or Handling of Exceptional Conditions'}, 'title': 'Uncaught exception in OpenBMC Firmware for the Intel® Server M50FCP Family and Intel® Server D50DNP Family before version R01.02.0002 may allow an authenticated user to potentially enable denial of service via network access. ', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 4.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'NONE', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'LOW', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'NONE'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-25191', 'cwe': {'id': 'CWE-284', 'name': 'Improper Access Control'}, 'title': 'Improper access control in AMI BMC firmware for the Intel® Server Board M70KLP, Intel® Server M20NTP, and Intel® Server Board M10JNP before versions 4.16, 0027.D02 and 7.220 may allow an unauthenticated user to enable escalation of privilege via network access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.1, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'NONE', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'NONE', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-25192', 'cwe': {'id': 'CWE-522', 'name': 'Insufficiently Protected Credentials'}, 'title': 'Insufficiently protected credentials in AMI BMC firmware for Intel® Server Board M70KLP, Intel® Server M20NTP, and Intel® Server Board M10JNP products before before versions 4.16, 0027.D02 and 7.220 may allow an unauthenticated user to enable information disclosure via network access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N', 'userInteraction': 'PASSIVE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'NONE', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'NONE', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'NONE', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'LOW'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-29164', 'cwe': {'id': 'CWE-862', 'name': 'Missing Authorization'}, 'title': 'Improper access control in BMC Firmware for the Intel® Server Board S2600WF, Intel® Server Board S2600ST, Intel® Server Board S2600BP, before version 02.01.0017 and Intel® Server Board M50CYP and Intel® Server Board D50TNP before version R01.01.0009 may allow an authenticated user to enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 7.3, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'LOW'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.8, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'NONE', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'LOW'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-31276', 'cwe': {'id': 'CWE-122', 'name': 'Heap-based Buffer Overflow'}, 'title': 'Heap-based buffer overflow in BMC Firmware for the Intel® Server Board S2600WF, Intel® Server Board S2600ST, Intel® Server Board S2600BP, before version 02.01.0017 and Intel® Server Board M50CYP and Intel® Server Board D50TNP before version R01.01.0009 may allow a privileged user to enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 8.2, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'HIGH', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.4, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'HIGH', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'HIGH', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2023-25191 | INTEL-SA-00990 | Intel® Server Board BMC Firmware Advisory | Potential security vulnerabilities in some Intel® Server Board BMC Firmware may allow escalation of privilege, information disclosure or denial of service. Intel is releasing firmware updates to mitigate these potential vulnerabilities.
| MEDIUM | 2025-02-11 03:00:00+03:00 | 2025-02-11 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00990.html | ab0f1e889efc0e40e820ba0d03bf33e112ed3c7ac286bbea4e97ff23c1d7d931 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® Server Board BMC Firmware may allow escalation of privilege, information disclosure or denial of service. Intel is releasing firmware updates to mitigate these potential vulnerabilities.\r\n', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Updates for Intel® Server Board S2600WF Family can be found here.\r\nUpdates for Intel® Server Board S2600ST Family can be found here.\r\nUpdates for Intel® Server Board S2600BP Family can be found here. \xa0\r\nUpdates for Intel® Server Board M70KLP Family BMC Firmware can be found\xa0here.\r\nUpdates for Intel® Server M20NTP Family BMC Firmware can be found\xa0here.\r\nUpdates for Intel® Server Board M10JNP Family BMC Firmware can be found\xa0here.\xa0\r\nUpdates for Intel® Server Board M50CYP Family can be found here.\r\nUpdates for Intel® Server Board D50TNP Family can be found here.\xa0\r\nUpdates for Intel® Server M50FCP Family can be found here.\r\nUpdates for Intel® Server Board D50DNP Family can be found here.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Critical', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Server Board BMC Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-00990', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2025-02-11T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2025-02-11T00:00:00+00:00', 'initial_release_date': '2025-02-11T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00990.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Copyright © Intel Corporation All rights reserved.'}, 'acknowledgments': [{'names': ['CVE-2023-25191, CVE-2023-25192 were found internally by Intel employees. Intel would like to thank Alex Gutkin and Ignacio Hernandez.\xa0\r\nCVE-2023-31276 was found internally by Intel employees. Intel would like to thank Daniel Medina Velazquez and Thierry Fernandes Faria.\xa0\r\nCVE-2023-29164 was found internally by Intel employees. Intel would like to thank Tal Rosen, Benny Zeltser and Rami Sudai. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2025-20097', 'cwe': {'id': 'CWE-703', 'name': 'Improper Check or Handling of Exceptional Conditions'}, 'title': 'Uncaught exception in OpenBMC Firmware for the Intel® Server M50FCP Family and Intel® Server D50DNP Family before version R01.02.0002 may allow an authenticated user to potentially enable denial of service via network access. ', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 4.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'NONE', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'LOW', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'NONE'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-25191', 'cwe': {'id': 'CWE-284', 'name': 'Improper Access Control'}, 'title': 'Improper access control in AMI BMC firmware for the Intel® Server Board M70KLP, Intel® Server M20NTP, and Intel® Server Board M10JNP before versions 4.16, 0027.D02 and 7.220 may allow an unauthenticated user to enable escalation of privilege via network access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.1, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'NONE', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'NONE', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-25192', 'cwe': {'id': 'CWE-522', 'name': 'Insufficiently Protected Credentials'}, 'title': 'Insufficiently protected credentials in AMI BMC firmware for Intel® Server Board M70KLP, Intel® Server M20NTP, and Intel® Server Board M10JNP products before before versions 4.16, 0027.D02 and 7.220 may allow an unauthenticated user to enable information disclosure via network access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N', 'userInteraction': 'PASSIVE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'NONE', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'NONE', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'NONE', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'LOW'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-29164', 'cwe': {'id': 'CWE-862', 'name': 'Missing Authorization'}, 'title': 'Improper access control in BMC Firmware for the Intel® Server Board S2600WF, Intel® Server Board S2600ST, Intel® Server Board S2600BP, before version 02.01.0017 and Intel® Server Board M50CYP and Intel® Server Board D50TNP before version R01.01.0009 may allow an authenticated user to enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 7.3, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'LOW'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.8, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'NONE', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'LOW'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-31276', 'cwe': {'id': 'CWE-122', 'name': 'Heap-based Buffer Overflow'}, 'title': 'Heap-based buffer overflow in BMC Firmware for the Intel® Server Board S2600WF, Intel® Server Board S2600ST, Intel® Server Board S2600BP, before version 02.01.0017 and Intel® Server Board M50CYP and Intel® Server Board D50TNP before version R01.01.0009 may allow a privileged user to enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 8.2, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'HIGH', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.4, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'HIGH', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'HIGH', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2023-25192 | INTEL-SA-00990 | Intel® Server Board BMC Firmware Advisory | Potential security vulnerabilities in some Intel® Server Board BMC Firmware may allow escalation of privilege, information disclosure or denial of service. Intel is releasing firmware updates to mitigate these potential vulnerabilities.
| MEDIUM | 2025-02-11 03:00:00+03:00 | 2025-02-11 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00990.html | 115c71fcad171e00ea416b2a7bbaac1c948b78e9b52d852af710cb3fddb78484 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® Server Board BMC Firmware may allow escalation of privilege, information disclosure or denial of service. Intel is releasing firmware updates to mitigate these potential vulnerabilities.\r\n', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Updates for Intel® Server Board S2600WF Family can be found here.\r\nUpdates for Intel® Server Board S2600ST Family can be found here.\r\nUpdates for Intel® Server Board S2600BP Family can be found here. \xa0\r\nUpdates for Intel® Server Board M70KLP Family BMC Firmware can be found\xa0here.\r\nUpdates for Intel® Server M20NTP Family BMC Firmware can be found\xa0here.\r\nUpdates for Intel® Server Board M10JNP Family BMC Firmware can be found\xa0here.\xa0\r\nUpdates for Intel® Server Board M50CYP Family can be found here.\r\nUpdates for Intel® Server Board D50TNP Family can be found here.\xa0\r\nUpdates for Intel® Server M50FCP Family can be found here.\r\nUpdates for Intel® Server Board D50DNP Family can be found here.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Critical', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Server Board BMC Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-00990', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2025-02-11T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2025-02-11T00:00:00+00:00', 'initial_release_date': '2025-02-11T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00990.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Copyright © Intel Corporation All rights reserved.'}, 'acknowledgments': [{'names': ['CVE-2023-25191, CVE-2023-25192 were found internally by Intel employees. Intel would like to thank Alex Gutkin and Ignacio Hernandez.\xa0\r\nCVE-2023-31276 was found internally by Intel employees. Intel would like to thank Daniel Medina Velazquez and Thierry Fernandes Faria.\xa0\r\nCVE-2023-29164 was found internally by Intel employees. Intel would like to thank Tal Rosen, Benny Zeltser and Rami Sudai. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2025-20097', 'cwe': {'id': 'CWE-703', 'name': 'Improper Check or Handling of Exceptional Conditions'}, 'title': 'Uncaught exception in OpenBMC Firmware for the Intel® Server M50FCP Family and Intel® Server D50DNP Family before version R01.02.0002 may allow an authenticated user to potentially enable denial of service via network access. ', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 4.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'NONE', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'LOW', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'NONE'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-25191', 'cwe': {'id': 'CWE-284', 'name': 'Improper Access Control'}, 'title': 'Improper access control in AMI BMC firmware for the Intel® Server Board M70KLP, Intel® Server M20NTP, and Intel® Server Board M10JNP before versions 4.16, 0027.D02 and 7.220 may allow an unauthenticated user to enable escalation of privilege via network access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.1, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'NONE', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'NONE', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-25192', 'cwe': {'id': 'CWE-522', 'name': 'Insufficiently Protected Credentials'}, 'title': 'Insufficiently protected credentials in AMI BMC firmware for Intel® Server Board M70KLP, Intel® Server M20NTP, and Intel® Server Board M10JNP products before before versions 4.16, 0027.D02 and 7.220 may allow an unauthenticated user to enable information disclosure via network access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N', 'userInteraction': 'PASSIVE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'NONE', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'NONE', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'NONE', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'LOW'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-29164', 'cwe': {'id': 'CWE-862', 'name': 'Missing Authorization'}, 'title': 'Improper access control in BMC Firmware for the Intel® Server Board S2600WF, Intel® Server Board S2600ST, Intel® Server Board S2600BP, before version 02.01.0017 and Intel® Server Board M50CYP and Intel® Server Board D50TNP before version R01.01.0009 may allow an authenticated user to enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 7.3, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'LOW'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.8, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'NONE', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'LOW'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-31276', 'cwe': {'id': 'CWE-122', 'name': 'Heap-based Buffer Overflow'}, 'title': 'Heap-based buffer overflow in BMC Firmware for the Intel® Server Board S2600WF, Intel® Server Board S2600ST, Intel® Server Board S2600BP, before version 02.01.0017 and Intel® Server Board M50CYP and Intel® Server Board D50TNP before version R01.01.0009 may allow a privileged user to enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 8.2, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'HIGH', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.4, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'HIGH', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'HIGH', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2023-29164 | INTEL-SA-00990 | Intel® Server Board BMC Firmware Advisory | Potential security vulnerabilities in some Intel® Server Board BMC Firmware may allow escalation of privilege, information disclosure or denial of service. Intel is releasing firmware updates to mitigate these potential vulnerabilities.
| MEDIUM | 2025-02-11 03:00:00+03:00 | 2025-02-11 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00990.html | 0c2efeffb59da7020c571f160c74b8b704c9c2add020a151b3174c026de9ba95 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® Server Board BMC Firmware may allow escalation of privilege, information disclosure or denial of service. Intel is releasing firmware updates to mitigate these potential vulnerabilities.\r\n', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Updates for Intel® Server Board S2600WF Family can be found here.\r\nUpdates for Intel® Server Board S2600ST Family can be found here.\r\nUpdates for Intel® Server Board S2600BP Family can be found here. \xa0\r\nUpdates for Intel® Server Board M70KLP Family BMC Firmware can be found\xa0here.\r\nUpdates for Intel® Server M20NTP Family BMC Firmware can be found\xa0here.\r\nUpdates for Intel® Server Board M10JNP Family BMC Firmware can be found\xa0here.\xa0\r\nUpdates for Intel® Server Board M50CYP Family can be found here.\r\nUpdates for Intel® Server Board D50TNP Family can be found here.\xa0\r\nUpdates for Intel® Server M50FCP Family can be found here.\r\nUpdates for Intel® Server Board D50DNP Family can be found here.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Critical', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Server Board BMC Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-00990', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2025-02-11T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2025-02-11T00:00:00+00:00', 'initial_release_date': '2025-02-11T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00990.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Copyright © Intel Corporation All rights reserved.'}, 'acknowledgments': [{'names': ['CVE-2023-25191, CVE-2023-25192 were found internally by Intel employees. Intel would like to thank Alex Gutkin and Ignacio Hernandez.\xa0\r\nCVE-2023-31276 was found internally by Intel employees. Intel would like to thank Daniel Medina Velazquez and Thierry Fernandes Faria.\xa0\r\nCVE-2023-29164 was found internally by Intel employees. Intel would like to thank Tal Rosen, Benny Zeltser and Rami Sudai. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2025-20097', 'cwe': {'id': 'CWE-703', 'name': 'Improper Check or Handling of Exceptional Conditions'}, 'title': 'Uncaught exception in OpenBMC Firmware for the Intel® Server M50FCP Family and Intel® Server D50DNP Family before version R01.02.0002 may allow an authenticated user to potentially enable denial of service via network access. ', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 4.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'NONE', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'LOW', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'NONE'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-25191', 'cwe': {'id': 'CWE-284', 'name': 'Improper Access Control'}, 'title': 'Improper access control in AMI BMC firmware for the Intel® Server Board M70KLP, Intel® Server M20NTP, and Intel® Server Board M10JNP before versions 4.16, 0027.D02 and 7.220 may allow an unauthenticated user to enable escalation of privilege via network access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.1, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'NONE', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'NONE', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-25192', 'cwe': {'id': 'CWE-522', 'name': 'Insufficiently Protected Credentials'}, 'title': 'Insufficiently protected credentials in AMI BMC firmware for Intel® Server Board M70KLP, Intel® Server M20NTP, and Intel® Server Board M10JNP products before before versions 4.16, 0027.D02 and 7.220 may allow an unauthenticated user to enable information disclosure via network access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N', 'userInteraction': 'PASSIVE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'NONE', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'NONE', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'NONE', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'LOW'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-29164', 'cwe': {'id': 'CWE-862', 'name': 'Missing Authorization'}, 'title': 'Improper access control in BMC Firmware for the Intel® Server Board S2600WF, Intel® Server Board S2600ST, Intel® Server Board S2600BP, before version 02.01.0017 and Intel® Server Board M50CYP and Intel® Server Board D50TNP before version R01.01.0009 may allow an authenticated user to enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 7.3, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'LOW'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.8, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'NONE', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'LOW'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-31276', 'cwe': {'id': 'CWE-122', 'name': 'Heap-based Buffer Overflow'}, 'title': 'Heap-based buffer overflow in BMC Firmware for the Intel® Server Board S2600WF, Intel® Server Board S2600ST, Intel® Server Board S2600BP, before version 02.01.0017 and Intel® Server Board M50CYP and Intel® Server Board D50TNP before version R01.01.0009 may allow a privileged user to enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 8.2, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'HIGH', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.4, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'HIGH', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'HIGH', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2023-31276 | INTEL-SA-00990 | Intel® Server Board BMC Firmware Advisory | Potential security vulnerabilities in some Intel® Server Board BMC Firmware may allow escalation of privilege, information disclosure or denial of service. Intel is releasing firmware updates to mitigate these potential vulnerabilities.
| MEDIUM | 2025-02-11 03:00:00+03:00 | 2025-02-11 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00990.html | 3064593547288add6d0b9ccb760bfc9c45f7022d058770105343e695e64bb9b1 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® Server Board BMC Firmware may allow escalation of privilege, information disclosure or denial of service. Intel is releasing firmware updates to mitigate these potential vulnerabilities.\r\n', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Updates for Intel® Server Board S2600WF Family can be found here.\r\nUpdates for Intel® Server Board S2600ST Family can be found here.\r\nUpdates for Intel® Server Board S2600BP Family can be found here. \xa0\r\nUpdates for Intel® Server Board M70KLP Family BMC Firmware can be found\xa0here.\r\nUpdates for Intel® Server M20NTP Family BMC Firmware can be found\xa0here.\r\nUpdates for Intel® Server Board M10JNP Family BMC Firmware can be found\xa0here.\xa0\r\nUpdates for Intel® Server Board M50CYP Family can be found here.\r\nUpdates for Intel® Server Board D50TNP Family can be found here.\xa0\r\nUpdates for Intel® Server M50FCP Family can be found here.\r\nUpdates for Intel® Server Board D50DNP Family can be found here.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Critical', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Server Board BMC Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-00990', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2025-02-11T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2025-02-11T00:00:00+00:00', 'initial_release_date': '2025-02-11T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00990.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Copyright © Intel Corporation All rights reserved.'}, 'acknowledgments': [{'names': ['CVE-2023-25191, CVE-2023-25192 were found internally by Intel employees. Intel would like to thank Alex Gutkin and Ignacio Hernandez.\xa0\r\nCVE-2023-31276 was found internally by Intel employees. Intel would like to thank Daniel Medina Velazquez and Thierry Fernandes Faria.\xa0\r\nCVE-2023-29164 was found internally by Intel employees. Intel would like to thank Tal Rosen, Benny Zeltser and Rami Sudai. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2025-20097', 'cwe': {'id': 'CWE-703', 'name': 'Improper Check or Handling of Exceptional Conditions'}, 'title': 'Uncaught exception in OpenBMC Firmware for the Intel® Server M50FCP Family and Intel® Server D50DNP Family before version R01.02.0002 may allow an authenticated user to potentially enable denial of service via network access. ', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 4.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'NONE', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'LOW', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'NONE'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-25191', 'cwe': {'id': 'CWE-284', 'name': 'Improper Access Control'}, 'title': 'Improper access control in AMI BMC firmware for the Intel® Server Board M70KLP, Intel® Server M20NTP, and Intel® Server Board M10JNP before versions 4.16, 0027.D02 and 7.220 may allow an unauthenticated user to enable escalation of privilege via network access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.1, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 9.3, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'NONE', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'NONE', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-25192', 'cwe': {'id': 'CWE-522', 'name': 'Insufficiently Protected Credentials'}, 'title': 'Insufficiently protected credentials in AMI BMC firmware for Intel® Server Board M70KLP, Intel® Server M20NTP, and Intel® Server Board M10JNP products before before versions 4.16, 0027.D02 and 7.220 may allow an unauthenticated user to enable information disclosure via network access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N', 'userInteraction': 'PASSIVE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'NONE', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'NONE', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'NONE', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'LOW'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-29164', 'cwe': {'id': 'CWE-862', 'name': 'Missing Authorization'}, 'title': 'Improper access control in BMC Firmware for the Intel® Server Board S2600WF, Intel® Server Board S2600ST, Intel® Server Board S2600BP, before version 02.01.0017 and Intel® Server Board M50CYP and Intel® Server Board D50TNP before version R01.01.0009 may allow an authenticated user to enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 7.3, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'LOW'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.8, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'NONE', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'LOW'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-31276', 'cwe': {'id': 'CWE-122', 'name': 'Heap-based Buffer Overflow'}, 'title': 'Heap-based buffer overflow in BMC Firmware for the Intel® Server Board S2600WF, Intel® Server Board S2600ST, Intel® Server Board S2600BP, before version 02.01.0017 and Intel® Server Board M50CYP and Intel® Server Board D50TNP before version R01.01.0009 may allow a privileged user to enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 8.2, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'HIGH', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.4, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'HIGH', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'HIGH', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2023-34424 | INTEL-SA-00999 | 2024.3 IPU - Intel® Chipset Firmware Advisory | Potential security vulnerabilities in Intel® Converged Security and Manageability Engine (CSME), Intel® Active Management Technology (AMT), Intel® Standard Manageability, Intel® PROSet/Wireless and Intel® Killer™ Wi-Fi software may allow escalation of privilege, denial of service, or information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities. | MEDIUM | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00999.html | 25fb71e2d9a67c68776ad01337b9e5c0aa7a3dd6ab890663a58043fbbcd31381 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in Intel® Converged Security and Manageability Engine (CSME), Intel® Active Management Technology (AMT), Intel® Standard Manageability, Intel® PROSet/Wireless and Intel® Killer™ Wi-Fi software may allow escalation of privilege, denial of service, or information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of Intel® Converged Security and Manageability Engine (CSME), Intel® Active Management Technology (AMT), Intel® Standard Manageability, Intel® PROSet/Wireless and Intel® Killer™ Wi-Fi software\xa0 update to the latest version provided by the system manufacturer that addresses these issues.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': '2024.3 IPU - Intel® Chipset Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-00999', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00999.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['The following issues were found internally by Intel Employees.\xa0 Intel would like to thank Alexander Kantor and Ora Naki (CVE-2023-40067), Igor Metric (CVE-2024-21844), Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-34424', 'title': 'Improper input validation in firmware for some Intel® CSME may allow a privileged user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-38655', 'title': 'Improper buffer restrictions in firmware for some Intel® AMT and Intel® Standard Manageability may allow a privileged user to potentially enable denial of service via network access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-35061', 'title': 'Improper initialization for the Intel® PROSet/Wireless and Intel® Killer™ Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable information disclosure via adjacent access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 2.3, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21844', 'title': 'Integer overflow in firmware for some Intel® CSME may allow an unauthenticated user to potentially enable denial of service via adjacent access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-40067', 'title': 'Unchecked return value in firmware for some Intel® CSME may allow an unauthenticated user to potentially enable escalation of privilege via physical access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:P/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:L/SI:H/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-48361', 'title': 'Improper initialization in firmware for some Intel® CSME may allow a privileged user to potentially enable information disclosure via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 2.3, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 4.6, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2023-38655 | INTEL-SA-00999 | 2024.3 IPU - Intel® Chipset Firmware Advisory | Potential security vulnerabilities in Intel® Converged Security and Manageability Engine (CSME), Intel® Active Management Technology (AMT), Intel® Standard Manageability, Intel® PROSet/Wireless and Intel® Killer™ Wi-Fi software may allow escalation of privilege, denial of service, or information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities. | MEDIUM | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00999.html | cd70f6b7a142b2c7b2af58579292a96d1c2edb1d7c096e31e342f4724205b647 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in Intel® Converged Security and Manageability Engine (CSME), Intel® Active Management Technology (AMT), Intel® Standard Manageability, Intel® PROSet/Wireless and Intel® Killer™ Wi-Fi software may allow escalation of privilege, denial of service, or information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of Intel® Converged Security and Manageability Engine (CSME), Intel® Active Management Technology (AMT), Intel® Standard Manageability, Intel® PROSet/Wireless and Intel® Killer™ Wi-Fi software\xa0 update to the latest version provided by the system manufacturer that addresses these issues.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': '2024.3 IPU - Intel® Chipset Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-00999', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00999.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['The following issues were found internally by Intel Employees.\xa0 Intel would like to thank Alexander Kantor and Ora Naki (CVE-2023-40067), Igor Metric (CVE-2024-21844), Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-34424', 'title': 'Improper input validation in firmware for some Intel® CSME may allow a privileged user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-38655', 'title': 'Improper buffer restrictions in firmware for some Intel® AMT and Intel® Standard Manageability may allow a privileged user to potentially enable denial of service via network access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-35061', 'title': 'Improper initialization for the Intel® PROSet/Wireless and Intel® Killer™ Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable information disclosure via adjacent access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 2.3, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21844', 'title': 'Integer overflow in firmware for some Intel® CSME may allow an unauthenticated user to potentially enable denial of service via adjacent access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-40067', 'title': 'Unchecked return value in firmware for some Intel® CSME may allow an unauthenticated user to potentially enable escalation of privilege via physical access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:P/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:L/SI:H/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-48361', 'title': 'Improper initialization in firmware for some Intel® CSME may allow a privileged user to potentially enable information disclosure via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 2.3, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 4.6, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2023-35061 | INTEL-SA-00999 | 2024.3 IPU - Intel® Chipset Firmware Advisory | Potential security vulnerabilities in Intel® Converged Security and Manageability Engine (CSME), Intel® Active Management Technology (AMT), Intel® Standard Manageability, Intel® PROSet/Wireless and Intel® Killer™ Wi-Fi software may allow escalation of privilege, denial of service, or information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities. | MEDIUM | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00999.html | 6064a0584d56804d9c53a9cf73eaf0bad1c5963103340a511ff2fb1740a76c08 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in Intel® Converged Security and Manageability Engine (CSME), Intel® Active Management Technology (AMT), Intel® Standard Manageability, Intel® PROSet/Wireless and Intel® Killer™ Wi-Fi software may allow escalation of privilege, denial of service, or information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of Intel® Converged Security and Manageability Engine (CSME), Intel® Active Management Technology (AMT), Intel® Standard Manageability, Intel® PROSet/Wireless and Intel® Killer™ Wi-Fi software\xa0 update to the latest version provided by the system manufacturer that addresses these issues.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': '2024.3 IPU - Intel® Chipset Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-00999', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00999.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['The following issues were found internally by Intel Employees.\xa0 Intel would like to thank Alexander Kantor and Ora Naki (CVE-2023-40067), Igor Metric (CVE-2024-21844), Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-34424', 'title': 'Improper input validation in firmware for some Intel® CSME may allow a privileged user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-38655', 'title': 'Improper buffer restrictions in firmware for some Intel® AMT and Intel® Standard Manageability may allow a privileged user to potentially enable denial of service via network access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-35061', 'title': 'Improper initialization for the Intel® PROSet/Wireless and Intel® Killer™ Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable information disclosure via adjacent access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 2.3, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21844', 'title': 'Integer overflow in firmware for some Intel® CSME may allow an unauthenticated user to potentially enable denial of service via adjacent access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-40067', 'title': 'Unchecked return value in firmware for some Intel® CSME may allow an unauthenticated user to potentially enable escalation of privilege via physical access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:P/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:L/SI:H/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-48361', 'title': 'Improper initialization in firmware for some Intel® CSME may allow a privileged user to potentially enable information disclosure via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 2.3, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 4.6, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-21844 | INTEL-SA-00999 | 2024.3 IPU - Intel® Chipset Firmware Advisory | Potential security vulnerabilities in Intel® Converged Security and Manageability Engine (CSME), Intel® Active Management Technology (AMT), Intel® Standard Manageability, Intel® PROSet/Wireless and Intel® Killer™ Wi-Fi software may allow escalation of privilege, denial of service, or information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities. | MEDIUM | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00999.html | 7c9a91fa2c95fe2630bf29096ea412dff9459bf728b349dd8287cb22e789aab2 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in Intel® Converged Security and Manageability Engine (CSME), Intel® Active Management Technology (AMT), Intel® Standard Manageability, Intel® PROSet/Wireless and Intel® Killer™ Wi-Fi software may allow escalation of privilege, denial of service, or information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of Intel® Converged Security and Manageability Engine (CSME), Intel® Active Management Technology (AMT), Intel® Standard Manageability, Intel® PROSet/Wireless and Intel® Killer™ Wi-Fi software\xa0 update to the latest version provided by the system manufacturer that addresses these issues.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': '2024.3 IPU - Intel® Chipset Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-00999', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00999.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['The following issues were found internally by Intel Employees.\xa0 Intel would like to thank Alexander Kantor and Ora Naki (CVE-2023-40067), Igor Metric (CVE-2024-21844), Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-34424', 'title': 'Improper input validation in firmware for some Intel® CSME may allow a privileged user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-38655', 'title': 'Improper buffer restrictions in firmware for some Intel® AMT and Intel® Standard Manageability may allow a privileged user to potentially enable denial of service via network access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-35061', 'title': 'Improper initialization for the Intel® PROSet/Wireless and Intel® Killer™ Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable information disclosure via adjacent access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 2.3, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21844', 'title': 'Integer overflow in firmware for some Intel® CSME may allow an unauthenticated user to potentially enable denial of service via adjacent access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-40067', 'title': 'Unchecked return value in firmware for some Intel® CSME may allow an unauthenticated user to potentially enable escalation of privilege via physical access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:P/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:L/SI:H/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-48361', 'title': 'Improper initialization in firmware for some Intel® CSME may allow a privileged user to potentially enable information disclosure via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 2.3, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 4.6, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2023-40067 | INTEL-SA-00999 | 2024.3 IPU - Intel® Chipset Firmware Advisory | Potential security vulnerabilities in Intel® Converged Security and Manageability Engine (CSME), Intel® Active Management Technology (AMT), Intel® Standard Manageability, Intel® PROSet/Wireless and Intel® Killer™ Wi-Fi software may allow escalation of privilege, denial of service, or information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities. | MEDIUM | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00999.html | 64cfd921f7e6df9e26a5e688f96b222a90f37d93b6bffce0b4d1f8f675187077 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in Intel® Converged Security and Manageability Engine (CSME), Intel® Active Management Technology (AMT), Intel® Standard Manageability, Intel® PROSet/Wireless and Intel® Killer™ Wi-Fi software may allow escalation of privilege, denial of service, or information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of Intel® Converged Security and Manageability Engine (CSME), Intel® Active Management Technology (AMT), Intel® Standard Manageability, Intel® PROSet/Wireless and Intel® Killer™ Wi-Fi software\xa0 update to the latest version provided by the system manufacturer that addresses these issues.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': '2024.3 IPU - Intel® Chipset Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-00999', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00999.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['The following issues were found internally by Intel Employees.\xa0 Intel would like to thank Alexander Kantor and Ora Naki (CVE-2023-40067), Igor Metric (CVE-2024-21844), Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-34424', 'title': 'Improper input validation in firmware for some Intel® CSME may allow a privileged user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-38655', 'title': 'Improper buffer restrictions in firmware for some Intel® AMT and Intel® Standard Manageability may allow a privileged user to potentially enable denial of service via network access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-35061', 'title': 'Improper initialization for the Intel® PROSet/Wireless and Intel® Killer™ Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable information disclosure via adjacent access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 2.3, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21844', 'title': 'Integer overflow in firmware for some Intel® CSME may allow an unauthenticated user to potentially enable denial of service via adjacent access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-40067', 'title': 'Unchecked return value in firmware for some Intel® CSME may allow an unauthenticated user to potentially enable escalation of privilege via physical access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:P/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:L/SI:H/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-48361', 'title': 'Improper initialization in firmware for some Intel® CSME may allow a privileged user to potentially enable information disclosure via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 2.3, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 4.6, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2023-48361 | INTEL-SA-00999 | 2024.3 IPU - Intel® Chipset Firmware Advisory | Potential security vulnerabilities in Intel® Converged Security and Manageability Engine (CSME), Intel® Active Management Technology (AMT), Intel® Standard Manageability, Intel® PROSet/Wireless and Intel® Killer™ Wi-Fi software may allow escalation of privilege, denial of service, or information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities. | MEDIUM | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00999.html | 77631556cded0cd56921a70b43241178465da02667ae1676ebe664b5b5cf69bd | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in Intel® Converged Security and Manageability Engine (CSME), Intel® Active Management Technology (AMT), Intel® Standard Manageability, Intel® PROSet/Wireless and Intel® Killer™ Wi-Fi software may allow escalation of privilege, denial of service, or information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of Intel® Converged Security and Manageability Engine (CSME), Intel® Active Management Technology (AMT), Intel® Standard Manageability, Intel® PROSet/Wireless and Intel® Killer™ Wi-Fi software\xa0 update to the latest version provided by the system manufacturer that addresses these issues.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': '2024.3 IPU - Intel® Chipset Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-00999', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00999.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['The following issues were found internally by Intel Employees.\xa0 Intel would like to thank Alexander Kantor and Ora Naki (CVE-2023-40067), Igor Metric (CVE-2024-21844), Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-34424', 'title': 'Improper input validation in firmware for some Intel® CSME may allow a privileged user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-38655', 'title': 'Improper buffer restrictions in firmware for some Intel® AMT and Intel® Standard Manageability may allow a privileged user to potentially enable denial of service via network access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-35061', 'title': 'Improper initialization for the Intel® PROSet/Wireless and Intel® Killer™ Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable information disclosure via adjacent access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 2.3, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21844', 'title': 'Integer overflow in firmware for some Intel® CSME may allow an unauthenticated user to potentially enable denial of service via adjacent access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-40067', 'title': 'Unchecked return value in firmware for some Intel® CSME may allow an unauthenticated user to potentially enable escalation of privilege via physical access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:P/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:L/SI:H/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-48361', 'title': 'Improper initialization in firmware for some Intel® CSME may allow a privileged user to potentially enable information disclosure via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 2.3, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 4.6, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-39283 | INTEL-SA-01010 | Intel® TDX Module Software Advisory | A potential security vulnerability in Intel® Trust Domain Extensions (TDX) module software may allow escalation of privilege. Intel is releasing firmware updates to mitigate this potential vulnerability. | MEDIUM | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01010.html | 947fdd10dcf92d7394db7010bb518d95a3dae6d08d560fea9397a41756fc279f | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in Intel® Trust Domain Extensions (TDX) module software may allow escalation of privilege. Intel is releasing firmware updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating the TDX module software to version TDX 1.5.01.02.595 or later.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® TDX Module Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01010', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01010.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank Maxime Villard from Microsoft for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-39283', 'title': 'Incomplete filtering of special elements in Intel® TDX module software before version TDX_1.5.01.00.592 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2023-45229 | INTEL-SA-01022 | Intel® NUC BIOS Firmware Advisory | Potential security vulnerabilities in some Intel® NUC BIOS Firmware may allow escalation of privilege, denial of service, information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities. | MEDIUM | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01022.html | dde43b5ce3cec4f159acc5fb7858b966c62cf5244198f07874d08cb6c85f3dc0 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® NUC BIOS Firmware may allow escalation of privilege, denial of service, information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating the affected Intel® NUC BIOS firmware to the latest version\xa0\r\n\r\nIntel® NUC X15 Laptop Kits\r\n\r\nDownload Link\r\n\r\nLAPAC71G, LAPAC71H\r\n\r\nACADL357.0065\r\n\r\nLAPBC510, LAPBC710\r\n\r\nBCTGL357.0083\r\n\r\nLAPRC510, LAPRC710\r\n\r\nRCADL357.0066\r\n\r\nLAPKC51E, LAPKC71E, LAPKC71F\r\n\r\nKCTGL357.0048', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® NUC BIOS Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01022', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01022.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank Yngweijw\xa0 (CVE-2024-34163) for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-45229', 'title': "EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing the IA_NA or IA_TA option in a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2022-36763', 'title': 'EDK2 is susceptible to a vulnerability in the Tcg2MeasureGptTable() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45231', 'title': "EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing Neighbor Discovery Redirect message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45232', 'title': "EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45237', 'title': "EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45235', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability when handling Server ID option from a DHCPv6 proxy Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45230', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability via a long server ID option in DHCPv6 client. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45236', 'title': "EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-34163', 'title': 'Improper input validation in firmware for some Intel® NUC may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-39539', 'title': 'AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a PNG Logo file with dangerous type by Local access. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45233', 'title': "EDK2's Network Package is susceptible to an infinite lop vulnerability when parsing a PadN option in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45234', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability when processing DNS Servers option from a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2022-36763 | INTEL-SA-01022 | Intel® NUC BIOS Firmware Advisory | Potential security vulnerabilities in some Intel® NUC BIOS Firmware may allow escalation of privilege, denial of service, information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities. | MEDIUM | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01022.html | b0a5ef6cdc0371c9edff9c3906798f86112a935bb6235de8954bf142b8f2dab5 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® NUC BIOS Firmware may allow escalation of privilege, denial of service, information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating the affected Intel® NUC BIOS firmware to the latest version\xa0\r\n\r\nIntel® NUC X15 Laptop Kits\r\n\r\nDownload Link\r\n\r\nLAPAC71G, LAPAC71H\r\n\r\nACADL357.0065\r\n\r\nLAPBC510, LAPBC710\r\n\r\nBCTGL357.0083\r\n\r\nLAPRC510, LAPRC710\r\n\r\nRCADL357.0066\r\n\r\nLAPKC51E, LAPKC71E, LAPKC71F\r\n\r\nKCTGL357.0048', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® NUC BIOS Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01022', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01022.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank Yngweijw\xa0 (CVE-2024-34163) for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-45229', 'title': "EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing the IA_NA or IA_TA option in a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2022-36763', 'title': 'EDK2 is susceptible to a vulnerability in the Tcg2MeasureGptTable() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45231', 'title': "EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing Neighbor Discovery Redirect message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45232', 'title': "EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45237', 'title': "EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45235', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability when handling Server ID option from a DHCPv6 proxy Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45230', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability via a long server ID option in DHCPv6 client. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45236', 'title': "EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-34163', 'title': 'Improper input validation in firmware for some Intel® NUC may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-39539', 'title': 'AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a PNG Logo file with dangerous type by Local access. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45233', 'title': "EDK2's Network Package is susceptible to an infinite lop vulnerability when parsing a PadN option in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45234', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability when processing DNS Servers option from a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2023-45231 | INTEL-SA-01022 | Intel® NUC BIOS Firmware Advisory | Potential security vulnerabilities in some Intel® NUC BIOS Firmware may allow escalation of privilege, denial of service, information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities. | MEDIUM | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01022.html | f601d29e9786d49e1ff98315446c3a71049eee0960937e8fa840fc9b8f8778a5 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® NUC BIOS Firmware may allow escalation of privilege, denial of service, information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating the affected Intel® NUC BIOS firmware to the latest version\xa0\r\n\r\nIntel® NUC X15 Laptop Kits\r\n\r\nDownload Link\r\n\r\nLAPAC71G, LAPAC71H\r\n\r\nACADL357.0065\r\n\r\nLAPBC510, LAPBC710\r\n\r\nBCTGL357.0083\r\n\r\nLAPRC510, LAPRC710\r\n\r\nRCADL357.0066\r\n\r\nLAPKC51E, LAPKC71E, LAPKC71F\r\n\r\nKCTGL357.0048', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® NUC BIOS Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01022', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01022.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank Yngweijw\xa0 (CVE-2024-34163) for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-45229', 'title': "EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing the IA_NA or IA_TA option in a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2022-36763', 'title': 'EDK2 is susceptible to a vulnerability in the Tcg2MeasureGptTable() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45231', 'title': "EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing Neighbor Discovery Redirect message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45232', 'title': "EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45237', 'title': "EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45235', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability when handling Server ID option from a DHCPv6 proxy Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45230', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability via a long server ID option in DHCPv6 client. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45236', 'title': "EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-34163', 'title': 'Improper input validation in firmware for some Intel® NUC may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-39539', 'title': 'AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a PNG Logo file with dangerous type by Local access. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45233', 'title': "EDK2's Network Package is susceptible to an infinite lop vulnerability when parsing a PadN option in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45234', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability when processing DNS Servers option from a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2023-45232 | INTEL-SA-01022 | Intel® NUC BIOS Firmware Advisory | Potential security vulnerabilities in some Intel® NUC BIOS Firmware may allow escalation of privilege, denial of service, information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities. | MEDIUM | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01022.html | 1d4abf52a83f963db42d64c2013d263c23437fd2f75c44cca41988f62cc38fb7 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® NUC BIOS Firmware may allow escalation of privilege, denial of service, information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating the affected Intel® NUC BIOS firmware to the latest version\xa0\r\n\r\nIntel® NUC X15 Laptop Kits\r\n\r\nDownload Link\r\n\r\nLAPAC71G, LAPAC71H\r\n\r\nACADL357.0065\r\n\r\nLAPBC510, LAPBC710\r\n\r\nBCTGL357.0083\r\n\r\nLAPRC510, LAPRC710\r\n\r\nRCADL357.0066\r\n\r\nLAPKC51E, LAPKC71E, LAPKC71F\r\n\r\nKCTGL357.0048', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® NUC BIOS Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01022', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01022.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank Yngweijw\xa0 (CVE-2024-34163) for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-45229', 'title': "EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing the IA_NA or IA_TA option in a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2022-36763', 'title': 'EDK2 is susceptible to a vulnerability in the Tcg2MeasureGptTable() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45231', 'title': "EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing Neighbor Discovery Redirect message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45232', 'title': "EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45237', 'title': "EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45235', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability when handling Server ID option from a DHCPv6 proxy Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45230', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability via a long server ID option in DHCPv6 client. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45236', 'title': "EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-34163', 'title': 'Improper input validation in firmware for some Intel® NUC may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-39539', 'title': 'AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a PNG Logo file with dangerous type by Local access. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45233', 'title': "EDK2's Network Package is susceptible to an infinite lop vulnerability when parsing a PadN option in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45234', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability when processing DNS Servers option from a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2023-45237 | INTEL-SA-01022 | Intel® NUC BIOS Firmware Advisory | Potential security vulnerabilities in some Intel® NUC BIOS Firmware may allow escalation of privilege, denial of service, information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities. | MEDIUM | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01022.html | 651af2c27c1b629cfc3a564e48efd99290465f66c5b540e9da8d12283f57dc9d | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® NUC BIOS Firmware may allow escalation of privilege, denial of service, information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating the affected Intel® NUC BIOS firmware to the latest version\xa0\r\n\r\nIntel® NUC X15 Laptop Kits\r\n\r\nDownload Link\r\n\r\nLAPAC71G, LAPAC71H\r\n\r\nACADL357.0065\r\n\r\nLAPBC510, LAPBC710\r\n\r\nBCTGL357.0083\r\n\r\nLAPRC510, LAPRC710\r\n\r\nRCADL357.0066\r\n\r\nLAPKC51E, LAPKC71E, LAPKC71F\r\n\r\nKCTGL357.0048', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® NUC BIOS Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01022', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01022.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank Yngweijw\xa0 (CVE-2024-34163) for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-45229', 'title': "EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing the IA_NA or IA_TA option in a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2022-36763', 'title': 'EDK2 is susceptible to a vulnerability in the Tcg2MeasureGptTable() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45231', 'title': "EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing Neighbor Discovery Redirect message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45232', 'title': "EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45237', 'title': "EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45235', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability when handling Server ID option from a DHCPv6 proxy Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45230', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability via a long server ID option in DHCPv6 client. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45236', 'title': "EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-34163', 'title': 'Improper input validation in firmware for some Intel® NUC may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-39539', 'title': 'AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a PNG Logo file with dangerous type by Local access. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45233', 'title': "EDK2's Network Package is susceptible to an infinite lop vulnerability when parsing a PadN option in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45234', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability when processing DNS Servers option from a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2023-45235 | INTEL-SA-01022 | Intel® NUC BIOS Firmware Advisory | Potential security vulnerabilities in some Intel® NUC BIOS Firmware may allow escalation of privilege, denial of service, information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities. | MEDIUM | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01022.html | bf5a9510e574860df0567c720cdb85dbc0851803d6a684fb0936974d7e0fa685 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® NUC BIOS Firmware may allow escalation of privilege, denial of service, information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating the affected Intel® NUC BIOS firmware to the latest version\xa0\r\n\r\nIntel® NUC X15 Laptop Kits\r\n\r\nDownload Link\r\n\r\nLAPAC71G, LAPAC71H\r\n\r\nACADL357.0065\r\n\r\nLAPBC510, LAPBC710\r\n\r\nBCTGL357.0083\r\n\r\nLAPRC510, LAPRC710\r\n\r\nRCADL357.0066\r\n\r\nLAPKC51E, LAPKC71E, LAPKC71F\r\n\r\nKCTGL357.0048', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® NUC BIOS Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01022', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01022.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank Yngweijw\xa0 (CVE-2024-34163) for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-45229', 'title': "EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing the IA_NA or IA_TA option in a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2022-36763', 'title': 'EDK2 is susceptible to a vulnerability in the Tcg2MeasureGptTable() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45231', 'title': "EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing Neighbor Discovery Redirect message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45232', 'title': "EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45237', 'title': "EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45235', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability when handling Server ID option from a DHCPv6 proxy Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45230', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability via a long server ID option in DHCPv6 client. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45236', 'title': "EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-34163', 'title': 'Improper input validation in firmware for some Intel® NUC may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-39539', 'title': 'AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a PNG Logo file with dangerous type by Local access. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45233', 'title': "EDK2's Network Package is susceptible to an infinite lop vulnerability when parsing a PadN option in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45234', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability when processing DNS Servers option from a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2023-45230 | INTEL-SA-01022 | Intel® NUC BIOS Firmware Advisory | Potential security vulnerabilities in some Intel® NUC BIOS Firmware may allow escalation of privilege, denial of service, information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities. | MEDIUM | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01022.html | f7156b0a42122496ff6487d5c2bd8da21ad43ecf8fe8bfa5746a83a568e3eb02 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® NUC BIOS Firmware may allow escalation of privilege, denial of service, information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating the affected Intel® NUC BIOS firmware to the latest version\xa0\r\n\r\nIntel® NUC X15 Laptop Kits\r\n\r\nDownload Link\r\n\r\nLAPAC71G, LAPAC71H\r\n\r\nACADL357.0065\r\n\r\nLAPBC510, LAPBC710\r\n\r\nBCTGL357.0083\r\n\r\nLAPRC510, LAPRC710\r\n\r\nRCADL357.0066\r\n\r\nLAPKC51E, LAPKC71E, LAPKC71F\r\n\r\nKCTGL357.0048', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® NUC BIOS Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01022', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01022.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank Yngweijw\xa0 (CVE-2024-34163) for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-45229', 'title': "EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing the IA_NA or IA_TA option in a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2022-36763', 'title': 'EDK2 is susceptible to a vulnerability in the Tcg2MeasureGptTable() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45231', 'title': "EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing Neighbor Discovery Redirect message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45232', 'title': "EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45237', 'title': "EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45235', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability when handling Server ID option from a DHCPv6 proxy Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45230', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability via a long server ID option in DHCPv6 client. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45236', 'title': "EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-34163', 'title': 'Improper input validation in firmware for some Intel® NUC may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-39539', 'title': 'AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a PNG Logo file with dangerous type by Local access. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45233', 'title': "EDK2's Network Package is susceptible to an infinite lop vulnerability when parsing a PadN option in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45234', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability when processing DNS Servers option from a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2023-45236 | INTEL-SA-01022 | Intel® NUC BIOS Firmware Advisory | Potential security vulnerabilities in some Intel® NUC BIOS Firmware may allow escalation of privilege, denial of service, information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities. | MEDIUM | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01022.html | a46b01dbdaace6dcf77130c3ecd96d88a326624891e52de9e945c117c9cb40e1 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® NUC BIOS Firmware may allow escalation of privilege, denial of service, information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating the affected Intel® NUC BIOS firmware to the latest version\xa0\r\n\r\nIntel® NUC X15 Laptop Kits\r\n\r\nDownload Link\r\n\r\nLAPAC71G, LAPAC71H\r\n\r\nACADL357.0065\r\n\r\nLAPBC510, LAPBC710\r\n\r\nBCTGL357.0083\r\n\r\nLAPRC510, LAPRC710\r\n\r\nRCADL357.0066\r\n\r\nLAPKC51E, LAPKC71E, LAPKC71F\r\n\r\nKCTGL357.0048', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® NUC BIOS Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01022', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01022.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank Yngweijw\xa0 (CVE-2024-34163) for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-45229', 'title': "EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing the IA_NA or IA_TA option in a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2022-36763', 'title': 'EDK2 is susceptible to a vulnerability in the Tcg2MeasureGptTable() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45231', 'title': "EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing Neighbor Discovery Redirect message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45232', 'title': "EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45237', 'title': "EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45235', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability when handling Server ID option from a DHCPv6 proxy Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45230', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability via a long server ID option in DHCPv6 client. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45236', 'title': "EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-34163', 'title': 'Improper input validation in firmware for some Intel® NUC may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-39539', 'title': 'AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a PNG Logo file with dangerous type by Local access. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45233', 'title': "EDK2's Network Package is susceptible to an infinite lop vulnerability when parsing a PadN option in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45234', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability when processing DNS Servers option from a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-34163 | INTEL-SA-01022 | Intel® NUC BIOS Firmware Advisory | Potential security vulnerabilities in some Intel® NUC BIOS Firmware may allow escalation of privilege, denial of service, information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities. | MEDIUM | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01022.html | 35d3b0088dc2f4d77351eb738906eae89852eeb26ff52b995be6f3a576cf2b71 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® NUC BIOS Firmware may allow escalation of privilege, denial of service, information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating the affected Intel® NUC BIOS firmware to the latest version\xa0\r\n\r\nIntel® NUC X15 Laptop Kits\r\n\r\nDownload Link\r\n\r\nLAPAC71G, LAPAC71H\r\n\r\nACADL357.0065\r\n\r\nLAPBC510, LAPBC710\r\n\r\nBCTGL357.0083\r\n\r\nLAPRC510, LAPRC710\r\n\r\nRCADL357.0066\r\n\r\nLAPKC51E, LAPKC71E, LAPKC71F\r\n\r\nKCTGL357.0048', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® NUC BIOS Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01022', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01022.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank Yngweijw\xa0 (CVE-2024-34163) for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-45229', 'title': "EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing the IA_NA or IA_TA option in a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2022-36763', 'title': 'EDK2 is susceptible to a vulnerability in the Tcg2MeasureGptTable() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45231', 'title': "EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing Neighbor Discovery Redirect message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45232', 'title': "EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45237', 'title': "EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45235', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability when handling Server ID option from a DHCPv6 proxy Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45230', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability via a long server ID option in DHCPv6 client. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45236', 'title': "EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-34163', 'title': 'Improper input validation in firmware for some Intel® NUC may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-39539', 'title': 'AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a PNG Logo file with dangerous type by Local access. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45233', 'title': "EDK2's Network Package is susceptible to an infinite lop vulnerability when parsing a PadN option in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45234', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability when processing DNS Servers option from a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2023-39539 | INTEL-SA-01022 | Intel® NUC BIOS Firmware Advisory | Potential security vulnerabilities in some Intel® NUC BIOS Firmware may allow escalation of privilege, denial of service, information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities. | MEDIUM | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01022.html | cc256e9b365ae787f4a2bde96981af91669ae79500f676412e816deddd2b77dd | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® NUC BIOS Firmware may allow escalation of privilege, denial of service, information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating the affected Intel® NUC BIOS firmware to the latest version\xa0\r\n\r\nIntel® NUC X15 Laptop Kits\r\n\r\nDownload Link\r\n\r\nLAPAC71G, LAPAC71H\r\n\r\nACADL357.0065\r\n\r\nLAPBC510, LAPBC710\r\n\r\nBCTGL357.0083\r\n\r\nLAPRC510, LAPRC710\r\n\r\nRCADL357.0066\r\n\r\nLAPKC51E, LAPKC71E, LAPKC71F\r\n\r\nKCTGL357.0048', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® NUC BIOS Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01022', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01022.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank Yngweijw\xa0 (CVE-2024-34163) for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-45229', 'title': "EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing the IA_NA or IA_TA option in a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2022-36763', 'title': 'EDK2 is susceptible to a vulnerability in the Tcg2MeasureGptTable() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45231', 'title': "EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing Neighbor Discovery Redirect message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45232', 'title': "EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45237', 'title': "EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45235', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability when handling Server ID option from a DHCPv6 proxy Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45230', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability via a long server ID option in DHCPv6 client. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45236', 'title': "EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-34163', 'title': 'Improper input validation in firmware for some Intel® NUC may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-39539', 'title': 'AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a PNG Logo file with dangerous type by Local access. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45233', 'title': "EDK2's Network Package is susceptible to an infinite lop vulnerability when parsing a PadN option in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45234', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability when processing DNS Servers option from a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2023-45233 | INTEL-SA-01022 | Intel® NUC BIOS Firmware Advisory | Potential security vulnerabilities in some Intel® NUC BIOS Firmware may allow escalation of privilege, denial of service, information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities. | MEDIUM | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01022.html | b0770d10cb2cb2628c204eb27b9f5c5564d45cb2989ef61ea98cbb24c72814eb | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® NUC BIOS Firmware may allow escalation of privilege, denial of service, information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating the affected Intel® NUC BIOS firmware to the latest version\xa0\r\n\r\nIntel® NUC X15 Laptop Kits\r\n\r\nDownload Link\r\n\r\nLAPAC71G, LAPAC71H\r\n\r\nACADL357.0065\r\n\r\nLAPBC510, LAPBC710\r\n\r\nBCTGL357.0083\r\n\r\nLAPRC510, LAPRC710\r\n\r\nRCADL357.0066\r\n\r\nLAPKC51E, LAPKC71E, LAPKC71F\r\n\r\nKCTGL357.0048', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® NUC BIOS Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01022', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01022.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank Yngweijw\xa0 (CVE-2024-34163) for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-45229', 'title': "EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing the IA_NA or IA_TA option in a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2022-36763', 'title': 'EDK2 is susceptible to a vulnerability in the Tcg2MeasureGptTable() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45231', 'title': "EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing Neighbor Discovery Redirect message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45232', 'title': "EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45237', 'title': "EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45235', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability when handling Server ID option from a DHCPv6 proxy Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45230', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability via a long server ID option in DHCPv6 client. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45236', 'title': "EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-34163', 'title': 'Improper input validation in firmware for some Intel® NUC may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-39539', 'title': 'AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a PNG Logo file with dangerous type by Local access. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45233', 'title': "EDK2's Network Package is susceptible to an infinite lop vulnerability when parsing a PadN option in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45234', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability when processing DNS Servers option from a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2023-45234 | INTEL-SA-01022 | Intel® NUC BIOS Firmware Advisory | Potential security vulnerabilities in some Intel® NUC BIOS Firmware may allow escalation of privilege, denial of service, information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities. | MEDIUM | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01022.html | 35b001f3ef7dcc3847d8ba7ed2c0f133e5c93c8896ffc41e210fa7379afb4cec | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® NUC BIOS Firmware may allow escalation of privilege, denial of service, information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating the affected Intel® NUC BIOS firmware to the latest version\xa0\r\n\r\nIntel® NUC X15 Laptop Kits\r\n\r\nDownload Link\r\n\r\nLAPAC71G, LAPAC71H\r\n\r\nACADL357.0065\r\n\r\nLAPBC510, LAPBC710\r\n\r\nBCTGL357.0083\r\n\r\nLAPRC510, LAPRC710\r\n\r\nRCADL357.0066\r\n\r\nLAPKC51E, LAPKC71E, LAPKC71F\r\n\r\nKCTGL357.0048', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® NUC BIOS Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01022', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01022.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank Yngweijw\xa0 (CVE-2024-34163) for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-45229', 'title': "EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing the IA_NA or IA_TA option in a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2022-36763', 'title': 'EDK2 is susceptible to a vulnerability in the Tcg2MeasureGptTable() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45231', 'title': "EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing Neighbor Discovery Redirect message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45232', 'title': "EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45237', 'title': "EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45235', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability when handling Server ID option from a DHCPv6 proxy Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45230', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability via a long server ID option in DHCPv6 client. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45236', 'title': "EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-34163', 'title': 'Improper input validation in firmware for some Intel® NUC may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-39539', 'title': 'AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a PNG Logo file with dangerous type by Local access. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45233', 'title': "EDK2's Network Package is susceptible to an infinite lop vulnerability when parsing a PadN option in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-45234', 'title': "EDK2's Network Package is susceptible to a buffer overflow vulnerability when processing DNS Servers option from a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.", 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': None, 'baseSeverity': 'NONE', 'vectorString': ''}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-29076 | INTEL-SA-01024 | Intel® CST Software Advisory | A potential security vulnerability in some Intel® Context Sensing Technology (Intel® CST) software may allow denial of service. Intel is releasing software updates to mitigate these potential vulnerabilities. | MEDIUM | 2024-11-12 03:00:00+03:00 | 2024-11-12 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01024.html | d8c6f15c8a5b3163530c62433f54336b0f4d0924d32fb5080c8d7b265266d798 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® Context Sensing Technology (Intel® CST) software may allow denial of service. Intel is releasing software updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of Intel® CST software update to the latest version provided by the system manufacturer that addresses this issue.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Denial of Service', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® CST Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01024', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-11-12T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-11-12T00:00:00+00:00', 'initial_release_date': '2024-11-12T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01024.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Copyright © Intel Corporation All rights reserved.'}, 'acknowledgments': [{'names': ['This issue was found internally. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-29076', 'cwe': {'id': 'CWE-248', 'name': 'Uncaught Exception'}, 'title': 'Uncaught exception for some Intel® CST software before version 8.7.10803 may allow an authenticated user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.5, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.8, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'NONE', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'HIGH', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'NONE'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-39805 | INTEL-SA-01030 | Intel® Driver Support Assistant Software Advisory | A potential security vulnerability in some Intel® Driver Support Assistant (Intel® DSA) software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability. | HIGH | 2025-02-11 03:00:00+03:00 | 2025-02-11 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01030.html | c9d0d30696a061c847e592afcf53e847215a781a1ca94395af3c30b693bf59a2 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® Driver Support Assistant (Intel® DSA) software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating Intel® DSA software to version 23.4.39 or later.Updates are available for download at this location:https://www.intel.com/content/www/us/en/support/intel-driver-support-assistant.html', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': ' Intel® Driver Support Assistant Software Advisory ', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01030', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2025-02-11T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2025-02-11T00:00:00+00:00', 'initial_release_date': '2025-02-11T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01030.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Copyright © Intel Corporation All rights reserved.'}, 'acknowledgments': [{'names': ['Intel would like to thank @sim0nsecurity for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-39805', 'cwe': {'id': 'CWE-345', 'name': 'Insufficient Verification of Data Authenticity'}, 'title': 'Insufficient verification of data authenticity in some Intel® DSA software before version 23.4.39 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7.3, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'HIGH', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2023-42667 | INTEL-SA-01038 | Intel® Core™ Ultra Processor Stream Cache Advisory | A potential security vulnerability in the Intel® Core™ Ultra Processor stream cache mechanism may allow escalation of privilege. Intel is releasing microcode updates to mitigate this potential vulnerability. | HIGH | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01038.html | 0589e377c5a018126a5b040ebc29d2e9789eff84bccf8df35ddb159fac3ba5a8 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in the Intel® Core™ Ultra Processor stream cache mechanism may allow escalation of privilege. Intel is releasing microcode updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of affected Intel® Processors update to the latest version firmware provided by the system manufacturer that addresses these issues.\r\nIntel has released microcode version 0x17 for the affected Intel® Core™ Ultra processors that are currently supported on the public github repository.\r\nPlease see details below on access to the microcode:Public Github: https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files.\r\nThe microcode patch can be OS loaded.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Hardware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Core™ Ultra Processor Stream Cache Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01038', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01038.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['This issue was discovered internally by Intel employees. Intel would like to thanks Rober J Miller, Brent Calhoon, Priel Aharonian, Persio Morrobel Gomez and Paul Grosen for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-42667', 'title': 'Improper isolation in the Intel® Core™ Ultra Processor stream cache mechanism may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-21830 | INTEL-SA-01044 | Intel® VPL Software Advisory | A potential security vulnerability in some Intel® Video Processing Library (VPL) software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability. | MEDIUM | 2025-02-11 03:00:00+03:00 | 2025-02-11 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01044.html | d80c8b1be7c0e2f704ee68e0323fdf725d28bac034ea403eda304748b705b55d | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® Video Processing Library (VPL) software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating Intel® 7th-10th Gen Processor graphics for Windows to version 31.0.101.2130 or later.Updates are available for download at this location: \xa0https://www.intel.com/content/www/us/en/download/776137\xa0Intel recommends updating Intel® Arc™ & Iris® Xe graphics for Windows to version 31.0.101.5186_101.5234 or later.Updates are available for download at this location: \xa0https://www.intel.com/content/www/us/en/download/785597\xa0Intel recommends updating Intel® Arc™ Pro graphics for Windows to version 31.0.101.5319 or later.Updates are available for download at this location: \xa0https://www.intel.com/content/www/us/en/download/741626\xa0Intel recommends updating Intel® Data Center GPU Flex Series for Windows to version 31.0.101.5333 or later.Updates are available for download at this location: \xa0https://www.intel.com/content/www/us/en/download/780185\xa0Intel recommends updating Intel® VPL software to version 2023.4.0 or later.Updates are available for download at this location: \xa0https://github.com/intel/libvpl/releases', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® VPL Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01044', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2025-02-11T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2025-02-11T00:00:00+00:00', 'initial_release_date': '2025-02-11T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01044.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Copyright © Intel Corporation All rights reserved.'}, 'acknowledgments': [{'names': ['Intel would like to thank ycdxsb for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-21830', 'cwe': {'id': 'CWE-427', 'name': 'Uncontrolled Search Path Element'}, 'title': 'Uncontrolled search path in some Intel® VPL software before version 2023.4.0 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.7, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'HIGH', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'userInteraction': 'ACTIVE', 'attackComplexity': 'HIGH', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'HIGH', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2023-49141 | INTEL-SA-01046 | 2024.2 IPU - Intel® Processor Stream Cache Advisory | A potential security vulnerability in some Intel® Processor stream cache mechanisms may allow escalation of privilege. Intel is releasing microcode updates to mitigate this potential vulnerability. | HIGH | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01046.html | fbc19178d4d01b5adc3facd1e8be8644c3e3b6debbd4d6d4fcb8f32a49a7ac54 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® Processor stream cache mechanisms may allow escalation of privilege. Intel is releasing microcode updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of affected Intel® Processors update to the latest version firmware provided by the system manufacturer that addresses these issues.\r\nIntel has released microcode update for the affected products that are currently supported on the public github repository.\r\nPlease see details below on access to the microcode:Public Github: \xa0https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files.\r\nThe microcode patch can be OS loaded.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Hardware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': '2024.2 IPU - Intel® Processor Stream Cache Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01046', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01046.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['This issue was discovered internally by Intel employees. Intel would like to thanks Rober J Miller, Brent Calhoon, Priel Aharonian, Persio Morrobel Gomez and Paul Grosen for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-49141', 'title': 'Improper isolation in some Intel® Processors stream cache mechanism may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-21857 | INTEL-SA-01057 | Intel® oneAPI Compiler Software Advisory | A potential security vulnerability in some Intel® oneAPI Compiler software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability. | MEDIUM | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01057.html | f9b5d8577e7fe8aa5dcae77d76ceacf77b18305c50b270bb54576014503fa6f8 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® oneAPI Compiler software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating Intel® oneAPI DPC++/C++ Compiler to version 2024.1 or later.\r\nUpdates are available for download at this location:\r\nhttps://www.intel.com/content/www/us/en/developer/articles/tool/oneapi-standalone-components.html#dpcpp-cpp\r\n\xa0\r\nIntel recommends updating Intel® Fortran Compiler to version 2024.1 or later.\r\nUpdates are available for download at this location:\r\nhttps://www.intel.com/content/www/us/en/developer/articles/tool/oneapi-standalone-components.html#fortran\r\n\xa0\r\nIntel recommends updating Intel® oneAPI Base Toolkit to version 2024.1 or later.\r\nUpdates are available for download at this location:\r\nhttps://www.intel.com/content/www/us/en/developer/tools/oneapi/base-toolkit-download.html\r\n\xa0\r\nIntel recommends updating Intel® oneAPI HPC Toolkit to version 2024.1 or later.\r\nUpdates are available for download at this location:\r\nhttps://www.intel.com/content/www/us/en/developer/tools/oneapi/hpc-toolkit.html#gs.36knya\r\n\xa0\r\nIntel recommends updating Intel® Distribution for Python for Windows to version 2024.1 or later.\r\nUpdates are available for download at this location:\r\nhttps://www.intel.com/content/www/us/en/developer/tools/oneapi/distribution-for-python.html#gs.3slms1', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® oneAPI Compiler Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01057', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01057.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank ycdxsb for reporting this issue as well as Intel employee William Huhn. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-21857', 'title': 'Uncontrolled search path for some Intel® oneAPI Compiler software before version 2024.1 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-21801 | INTEL-SA-01070 | Intel® TDX Module Software Advisory | Potential security vulnerabily in some Intel® Trust Domain Extensions (Intel® TDX) module software may allow denial of service. Intel is releasing firmware updates to mitigate these potential vulnerabilities. | HIGH | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01070.html | 6b6cd539c4d877d5d63e16db906ec3c31cacc4026d601c3f3619c4b8a608c919 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabily in some Intel® Trust Domain Extensions (Intel® TDX) module software may allow denial of service. Intel is releasing firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of the Intel® TDX module update to the latest version provided by the system manufacturer that addresses these issues.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Hardware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Denial of Service', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® TDX Module Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01070', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01070.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['This issue was found internally by Intel. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-21801', 'title': 'Insufficient control flow management in some Intel® TDX module software before version 1.5.05.46.698 may allow a privileged user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.1, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2023-23904 | INTEL-SA-01071 | 2024.3 IPU - UEFI Firmware Advisory | Potential security vulnerabilities in UEFI firmware for some Intel® Processors may allow escalation of privilege, denial of service or information disclosure. Intel is releasing UEFI firmware updates to mitigate these potential vulnerabilities. | MEDIUM | 2024-09-10 03:00:00+03:00 | 2024-09-10 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01071.html | 9a1e1dafb8a1757adeeb945683527b4283b2030c6111d8ea8317ccf234a87865 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in UEFI firmware for some Intel® Processors may allow escalation of privilege, denial of service or information disclosure. Intel is releasing UEFI firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of Intel® Processors update to the latest version provided by the system manufacturer that addresses these issues.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': '2024.3 IPU - UEFI Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01071', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-09-10T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-09-10T00:00:00+00:00', 'initial_release_date': '2024-09-10T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01071.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['The following were found by Intel employees.\xa0 Intel would like to thank Ilya Alexandrovich (CVE-2023-43753) and Majid Shushtarian, Richard Thomaiyar, James Mihm, Vernon Maurey, Nilanthren (CVE-2024-23599).\r\nIntel would like to thank Phoenix Technologies (CVE-2023-43626), Yngweijw (CVE-2024-21871, CVE-2023-42772, CVE-2023-41833, CVE-2024-21829), Jeremy Boone (@uffeux) (CVE-2023-22351, CVE-2023-23904, CVE-2023-25546) for reporting these issues. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-23904', 'title': 'NULL pointer dereference in the UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-43626', 'title': 'Improper access control in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21781', 'title': 'Improper input validation in UEFI firmware for some Intel® Processors may allow a privileged user to enable information disclosure or denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:H/SC:H/SI:N/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23599', 'title': 'Race condition in Seamless Firmware Updates for some Intel® reference platforms may allow a privileged user to potentially enable denial of service via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.9, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21829', 'title': 'Improper input validation in UEFI firmware error handler for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-25546', 'title': 'Out-of-bounds read in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 2.5, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 1.8, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-43753', 'title': 'Improper conditions check in some Intel(R) Processors with Intel® Software Guard Extensions (Intel® SGX) may allow a privileged user to potentially enable information disclosure via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-42772', 'title': 'Untrusted pointer dereference in UEFI firmware for some Intel® reference processors may allow a privileged user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21871', 'title': 'Improper input validation in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-22351', 'title': 'Out-of-bounds write in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-41833', 'title': 'A race condition in UEFI firmware for some Intel® processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2023-43626 | INTEL-SA-01071 | 2024.3 IPU - UEFI Firmware Advisory | Potential security vulnerabilities in UEFI firmware for some Intel® Processors may allow escalation of privilege, denial of service or information disclosure. Intel is releasing UEFI firmware updates to mitigate these potential vulnerabilities. | MEDIUM | 2024-09-10 03:00:00+03:00 | 2024-09-10 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01071.html | 408ecf7ac24bba92924c19656cf9bd9aa5ec2cc71ad64110a7fa40a82edb0169 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in UEFI firmware for some Intel® Processors may allow escalation of privilege, denial of service or information disclosure. Intel is releasing UEFI firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of Intel® Processors update to the latest version provided by the system manufacturer that addresses these issues.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': '2024.3 IPU - UEFI Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01071', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-09-10T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-09-10T00:00:00+00:00', 'initial_release_date': '2024-09-10T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01071.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['The following were found by Intel employees.\xa0 Intel would like to thank Ilya Alexandrovich (CVE-2023-43753) and Majid Shushtarian, Richard Thomaiyar, James Mihm, Vernon Maurey, Nilanthren (CVE-2024-23599).\r\nIntel would like to thank Phoenix Technologies (CVE-2023-43626), Yngweijw (CVE-2024-21871, CVE-2023-42772, CVE-2023-41833, CVE-2024-21829), Jeremy Boone (@uffeux) (CVE-2023-22351, CVE-2023-23904, CVE-2023-25546) for reporting these issues. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-23904', 'title': 'NULL pointer dereference in the UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-43626', 'title': 'Improper access control in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21781', 'title': 'Improper input validation in UEFI firmware for some Intel® Processors may allow a privileged user to enable information disclosure or denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:H/SC:H/SI:N/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23599', 'title': 'Race condition in Seamless Firmware Updates for some Intel® reference platforms may allow a privileged user to potentially enable denial of service via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.9, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21829', 'title': 'Improper input validation in UEFI firmware error handler for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-25546', 'title': 'Out-of-bounds read in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 2.5, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 1.8, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-43753', 'title': 'Improper conditions check in some Intel(R) Processors with Intel® Software Guard Extensions (Intel® SGX) may allow a privileged user to potentially enable information disclosure via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-42772', 'title': 'Untrusted pointer dereference in UEFI firmware for some Intel® reference processors may allow a privileged user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21871', 'title': 'Improper input validation in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-22351', 'title': 'Out-of-bounds write in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-41833', 'title': 'A race condition in UEFI firmware for some Intel® processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-21781 | INTEL-SA-01071 | 2024.3 IPU - UEFI Firmware Advisory | Potential security vulnerabilities in UEFI firmware for some Intel® Processors may allow escalation of privilege, denial of service or information disclosure. Intel is releasing UEFI firmware updates to mitigate these potential vulnerabilities. | MEDIUM | 2024-09-10 03:00:00+03:00 | 2024-09-10 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01071.html | 60573c84a094988bf70cf49fd3b8a63e04a062778b6f521036cd71387884005c | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in UEFI firmware for some Intel® Processors may allow escalation of privilege, denial of service or information disclosure. Intel is releasing UEFI firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of Intel® Processors update to the latest version provided by the system manufacturer that addresses these issues.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': '2024.3 IPU - UEFI Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01071', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-09-10T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-09-10T00:00:00+00:00', 'initial_release_date': '2024-09-10T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01071.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['The following were found by Intel employees.\xa0 Intel would like to thank Ilya Alexandrovich (CVE-2023-43753) and Majid Shushtarian, Richard Thomaiyar, James Mihm, Vernon Maurey, Nilanthren (CVE-2024-23599).\r\nIntel would like to thank Phoenix Technologies (CVE-2023-43626), Yngweijw (CVE-2024-21871, CVE-2023-42772, CVE-2023-41833, CVE-2024-21829), Jeremy Boone (@uffeux) (CVE-2023-22351, CVE-2023-23904, CVE-2023-25546) for reporting these issues. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-23904', 'title': 'NULL pointer dereference in the UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-43626', 'title': 'Improper access control in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21781', 'title': 'Improper input validation in UEFI firmware for some Intel® Processors may allow a privileged user to enable information disclosure or denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:H/SC:H/SI:N/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23599', 'title': 'Race condition in Seamless Firmware Updates for some Intel® reference platforms may allow a privileged user to potentially enable denial of service via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.9, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21829', 'title': 'Improper input validation in UEFI firmware error handler for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-25546', 'title': 'Out-of-bounds read in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 2.5, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 1.8, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-43753', 'title': 'Improper conditions check in some Intel(R) Processors with Intel® Software Guard Extensions (Intel® SGX) may allow a privileged user to potentially enable information disclosure via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-42772', 'title': 'Untrusted pointer dereference in UEFI firmware for some Intel® reference processors may allow a privileged user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21871', 'title': 'Improper input validation in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-22351', 'title': 'Out-of-bounds write in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-41833', 'title': 'A race condition in UEFI firmware for some Intel® processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-23599 | INTEL-SA-01071 | 2024.3 IPU - UEFI Firmware Advisory | Potential security vulnerabilities in UEFI firmware for some Intel® Processors may allow escalation of privilege, denial of service or information disclosure. Intel is releasing UEFI firmware updates to mitigate these potential vulnerabilities. | MEDIUM | 2024-09-10 03:00:00+03:00 | 2024-09-10 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01071.html | b6917e1226da47353e2cdf9f6b4003eabad41486a751d51f4c3beaa92bb03366 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in UEFI firmware for some Intel® Processors may allow escalation of privilege, denial of service or information disclosure. Intel is releasing UEFI firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of Intel® Processors update to the latest version provided by the system manufacturer that addresses these issues.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': '2024.3 IPU - UEFI Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01071', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-09-10T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-09-10T00:00:00+00:00', 'initial_release_date': '2024-09-10T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01071.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['The following were found by Intel employees.\xa0 Intel would like to thank Ilya Alexandrovich (CVE-2023-43753) and Majid Shushtarian, Richard Thomaiyar, James Mihm, Vernon Maurey, Nilanthren (CVE-2024-23599).\r\nIntel would like to thank Phoenix Technologies (CVE-2023-43626), Yngweijw (CVE-2024-21871, CVE-2023-42772, CVE-2023-41833, CVE-2024-21829), Jeremy Boone (@uffeux) (CVE-2023-22351, CVE-2023-23904, CVE-2023-25546) for reporting these issues. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-23904', 'title': 'NULL pointer dereference in the UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-43626', 'title': 'Improper access control in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21781', 'title': 'Improper input validation in UEFI firmware for some Intel® Processors may allow a privileged user to enable information disclosure or denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:H/SC:H/SI:N/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23599', 'title': 'Race condition in Seamless Firmware Updates for some Intel® reference platforms may allow a privileged user to potentially enable denial of service via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.9, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21829', 'title': 'Improper input validation in UEFI firmware error handler for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-25546', 'title': 'Out-of-bounds read in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 2.5, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 1.8, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-43753', 'title': 'Improper conditions check in some Intel(R) Processors with Intel® Software Guard Extensions (Intel® SGX) may allow a privileged user to potentially enable information disclosure via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-42772', 'title': 'Untrusted pointer dereference in UEFI firmware for some Intel® reference processors may allow a privileged user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21871', 'title': 'Improper input validation in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-22351', 'title': 'Out-of-bounds write in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-41833', 'title': 'A race condition in UEFI firmware for some Intel® processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-21829 | INTEL-SA-01071 | 2024.3 IPU - UEFI Firmware Advisory | Potential security vulnerabilities in UEFI firmware for some Intel® Processors may allow escalation of privilege, denial of service or information disclosure. Intel is releasing UEFI firmware updates to mitigate these potential vulnerabilities. | MEDIUM | 2024-09-10 03:00:00+03:00 | 2024-09-10 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01071.html | 4cdf9b8e38d45d402b99793747939ebdf81575f624c2cf9237ff9f6ece2b1ea0 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in UEFI firmware for some Intel® Processors may allow escalation of privilege, denial of service or information disclosure. Intel is releasing UEFI firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of Intel® Processors update to the latest version provided by the system manufacturer that addresses these issues.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': '2024.3 IPU - UEFI Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01071', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-09-10T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-09-10T00:00:00+00:00', 'initial_release_date': '2024-09-10T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01071.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['The following were found by Intel employees.\xa0 Intel would like to thank Ilya Alexandrovich (CVE-2023-43753) and Majid Shushtarian, Richard Thomaiyar, James Mihm, Vernon Maurey, Nilanthren (CVE-2024-23599).\r\nIntel would like to thank Phoenix Technologies (CVE-2023-43626), Yngweijw (CVE-2024-21871, CVE-2023-42772, CVE-2023-41833, CVE-2024-21829), Jeremy Boone (@uffeux) (CVE-2023-22351, CVE-2023-23904, CVE-2023-25546) for reporting these issues. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-23904', 'title': 'NULL pointer dereference in the UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-43626', 'title': 'Improper access control in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21781', 'title': 'Improper input validation in UEFI firmware for some Intel® Processors may allow a privileged user to enable information disclosure or denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:H/SC:H/SI:N/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23599', 'title': 'Race condition in Seamless Firmware Updates for some Intel® reference platforms may allow a privileged user to potentially enable denial of service via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.9, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21829', 'title': 'Improper input validation in UEFI firmware error handler for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-25546', 'title': 'Out-of-bounds read in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 2.5, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 1.8, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-43753', 'title': 'Improper conditions check in some Intel(R) Processors with Intel® Software Guard Extensions (Intel® SGX) may allow a privileged user to potentially enable information disclosure via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-42772', 'title': 'Untrusted pointer dereference in UEFI firmware for some Intel® reference processors may allow a privileged user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21871', 'title': 'Improper input validation in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-22351', 'title': 'Out-of-bounds write in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-41833', 'title': 'A race condition in UEFI firmware for some Intel® processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2023-25546 | INTEL-SA-01071 | 2024.3 IPU - UEFI Firmware Advisory | Potential security vulnerabilities in UEFI firmware for some Intel® Processors may allow escalation of privilege, denial of service or information disclosure. Intel is releasing UEFI firmware updates to mitigate these potential vulnerabilities. | MEDIUM | 2024-09-10 03:00:00+03:00 | 2024-09-10 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01071.html | 7162b9e3f51a28724f51ccafac990b6f75205a507771fa55d7d2abf11d9b7e29 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in UEFI firmware for some Intel® Processors may allow escalation of privilege, denial of service or information disclosure. Intel is releasing UEFI firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of Intel® Processors update to the latest version provided by the system manufacturer that addresses these issues.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': '2024.3 IPU - UEFI Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01071', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-09-10T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-09-10T00:00:00+00:00', 'initial_release_date': '2024-09-10T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01071.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['The following were found by Intel employees.\xa0 Intel would like to thank Ilya Alexandrovich (CVE-2023-43753) and Majid Shushtarian, Richard Thomaiyar, James Mihm, Vernon Maurey, Nilanthren (CVE-2024-23599).\r\nIntel would like to thank Phoenix Technologies (CVE-2023-43626), Yngweijw (CVE-2024-21871, CVE-2023-42772, CVE-2023-41833, CVE-2024-21829), Jeremy Boone (@uffeux) (CVE-2023-22351, CVE-2023-23904, CVE-2023-25546) for reporting these issues. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-23904', 'title': 'NULL pointer dereference in the UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-43626', 'title': 'Improper access control in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21781', 'title': 'Improper input validation in UEFI firmware for some Intel® Processors may allow a privileged user to enable information disclosure or denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:H/SC:H/SI:N/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23599', 'title': 'Race condition in Seamless Firmware Updates for some Intel® reference platforms may allow a privileged user to potentially enable denial of service via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.9, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21829', 'title': 'Improper input validation in UEFI firmware error handler for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-25546', 'title': 'Out-of-bounds read in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 2.5, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 1.8, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-43753', 'title': 'Improper conditions check in some Intel(R) Processors with Intel® Software Guard Extensions (Intel® SGX) may allow a privileged user to potentially enable information disclosure via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-42772', 'title': 'Untrusted pointer dereference in UEFI firmware for some Intel® reference processors may allow a privileged user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21871', 'title': 'Improper input validation in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-22351', 'title': 'Out-of-bounds write in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-41833', 'title': 'A race condition in UEFI firmware for some Intel® processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2023-43753 | INTEL-SA-01071 | 2024.3 IPU - UEFI Firmware Advisory | Potential security vulnerabilities in UEFI firmware for some Intel® Processors may allow escalation of privilege, denial of service or information disclosure. Intel is releasing UEFI firmware updates to mitigate these potential vulnerabilities. | MEDIUM | 2024-09-10 03:00:00+03:00 | 2024-09-10 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01071.html | 056be2e01279e53985e0d9d00e9ea13f1d41ebbba2910d787531cbcb00b6be4f | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in UEFI firmware for some Intel® Processors may allow escalation of privilege, denial of service or information disclosure. Intel is releasing UEFI firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of Intel® Processors update to the latest version provided by the system manufacturer that addresses these issues.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': '2024.3 IPU - UEFI Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01071', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-09-10T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-09-10T00:00:00+00:00', 'initial_release_date': '2024-09-10T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01071.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['The following were found by Intel employees.\xa0 Intel would like to thank Ilya Alexandrovich (CVE-2023-43753) and Majid Shushtarian, Richard Thomaiyar, James Mihm, Vernon Maurey, Nilanthren (CVE-2024-23599).\r\nIntel would like to thank Phoenix Technologies (CVE-2023-43626), Yngweijw (CVE-2024-21871, CVE-2023-42772, CVE-2023-41833, CVE-2024-21829), Jeremy Boone (@uffeux) (CVE-2023-22351, CVE-2023-23904, CVE-2023-25546) for reporting these issues. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-23904', 'title': 'NULL pointer dereference in the UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-43626', 'title': 'Improper access control in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21781', 'title': 'Improper input validation in UEFI firmware for some Intel® Processors may allow a privileged user to enable information disclosure or denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:H/SC:H/SI:N/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23599', 'title': 'Race condition in Seamless Firmware Updates for some Intel® reference platforms may allow a privileged user to potentially enable denial of service via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.9, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21829', 'title': 'Improper input validation in UEFI firmware error handler for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-25546', 'title': 'Out-of-bounds read in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 2.5, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 1.8, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-43753', 'title': 'Improper conditions check in some Intel(R) Processors with Intel® Software Guard Extensions (Intel® SGX) may allow a privileged user to potentially enable information disclosure via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-42772', 'title': 'Untrusted pointer dereference in UEFI firmware for some Intel® reference processors may allow a privileged user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21871', 'title': 'Improper input validation in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-22351', 'title': 'Out-of-bounds write in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-41833', 'title': 'A race condition in UEFI firmware for some Intel® processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2023-42772 | INTEL-SA-01071 | 2024.3 IPU - UEFI Firmware Advisory | Potential security vulnerabilities in UEFI firmware for some Intel® Processors may allow escalation of privilege, denial of service or information disclosure. Intel is releasing UEFI firmware updates to mitigate these potential vulnerabilities. | MEDIUM | 2024-09-10 03:00:00+03:00 | 2024-09-10 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01071.html | fca6103c1707ad7983db6d6531ec5156732048bceb75395c9f71dd23a08c3fc4 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in UEFI firmware for some Intel® Processors may allow escalation of privilege, denial of service or information disclosure. Intel is releasing UEFI firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of Intel® Processors update to the latest version provided by the system manufacturer that addresses these issues.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': '2024.3 IPU - UEFI Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01071', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-09-10T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-09-10T00:00:00+00:00', 'initial_release_date': '2024-09-10T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01071.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['The following were found by Intel employees.\xa0 Intel would like to thank Ilya Alexandrovich (CVE-2023-43753) and Majid Shushtarian, Richard Thomaiyar, James Mihm, Vernon Maurey, Nilanthren (CVE-2024-23599).\r\nIntel would like to thank Phoenix Technologies (CVE-2023-43626), Yngweijw (CVE-2024-21871, CVE-2023-42772, CVE-2023-41833, CVE-2024-21829), Jeremy Boone (@uffeux) (CVE-2023-22351, CVE-2023-23904, CVE-2023-25546) for reporting these issues. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-23904', 'title': 'NULL pointer dereference in the UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-43626', 'title': 'Improper access control in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21781', 'title': 'Improper input validation in UEFI firmware for some Intel® Processors may allow a privileged user to enable information disclosure or denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:H/SC:H/SI:N/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23599', 'title': 'Race condition in Seamless Firmware Updates for some Intel® reference platforms may allow a privileged user to potentially enable denial of service via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.9, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21829', 'title': 'Improper input validation in UEFI firmware error handler for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-25546', 'title': 'Out-of-bounds read in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 2.5, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 1.8, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-43753', 'title': 'Improper conditions check in some Intel(R) Processors with Intel® Software Guard Extensions (Intel® SGX) may allow a privileged user to potentially enable information disclosure via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-42772', 'title': 'Untrusted pointer dereference in UEFI firmware for some Intel® reference processors may allow a privileged user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21871', 'title': 'Improper input validation in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-22351', 'title': 'Out-of-bounds write in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-41833', 'title': 'A race condition in UEFI firmware for some Intel® processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-21871 | INTEL-SA-01071 | 2024.3 IPU - UEFI Firmware Advisory | Potential security vulnerabilities in UEFI firmware for some Intel® Processors may allow escalation of privilege, denial of service or information disclosure. Intel is releasing UEFI firmware updates to mitigate these potential vulnerabilities. | MEDIUM | 2024-09-10 03:00:00+03:00 | 2024-09-10 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01071.html | c4e0510c116199b8c793d54628b566d00e43e6dda89c2ab1dcce274505f72acf | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in UEFI firmware for some Intel® Processors may allow escalation of privilege, denial of service or information disclosure. Intel is releasing UEFI firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of Intel® Processors update to the latest version provided by the system manufacturer that addresses these issues.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': '2024.3 IPU - UEFI Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01071', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-09-10T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-09-10T00:00:00+00:00', 'initial_release_date': '2024-09-10T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01071.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['The following were found by Intel employees.\xa0 Intel would like to thank Ilya Alexandrovich (CVE-2023-43753) and Majid Shushtarian, Richard Thomaiyar, James Mihm, Vernon Maurey, Nilanthren (CVE-2024-23599).\r\nIntel would like to thank Phoenix Technologies (CVE-2023-43626), Yngweijw (CVE-2024-21871, CVE-2023-42772, CVE-2023-41833, CVE-2024-21829), Jeremy Boone (@uffeux) (CVE-2023-22351, CVE-2023-23904, CVE-2023-25546) for reporting these issues. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-23904', 'title': 'NULL pointer dereference in the UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-43626', 'title': 'Improper access control in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21781', 'title': 'Improper input validation in UEFI firmware for some Intel® Processors may allow a privileged user to enable information disclosure or denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:H/SC:H/SI:N/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23599', 'title': 'Race condition in Seamless Firmware Updates for some Intel® reference platforms may allow a privileged user to potentially enable denial of service via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.9, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21829', 'title': 'Improper input validation in UEFI firmware error handler for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-25546', 'title': 'Out-of-bounds read in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 2.5, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 1.8, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-43753', 'title': 'Improper conditions check in some Intel(R) Processors with Intel® Software Guard Extensions (Intel® SGX) may allow a privileged user to potentially enable information disclosure via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-42772', 'title': 'Untrusted pointer dereference in UEFI firmware for some Intel® reference processors may allow a privileged user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21871', 'title': 'Improper input validation in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-22351', 'title': 'Out-of-bounds write in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-41833', 'title': 'A race condition in UEFI firmware for some Intel® processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2023-22351 | INTEL-SA-01071 | 2024.3 IPU - UEFI Firmware Advisory | Potential security vulnerabilities in UEFI firmware for some Intel® Processors may allow escalation of privilege, denial of service or information disclosure. Intel is releasing UEFI firmware updates to mitigate these potential vulnerabilities. | MEDIUM | 2024-09-10 03:00:00+03:00 | 2024-09-10 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01071.html | d9df04e8cc36e3fdcdea55c84861e01d9d464df8ad752e9babe6b472b528f171 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in UEFI firmware for some Intel® Processors may allow escalation of privilege, denial of service or information disclosure. Intel is releasing UEFI firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of Intel® Processors update to the latest version provided by the system manufacturer that addresses these issues.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': '2024.3 IPU - UEFI Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01071', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-09-10T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-09-10T00:00:00+00:00', 'initial_release_date': '2024-09-10T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01071.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['The following were found by Intel employees.\xa0 Intel would like to thank Ilya Alexandrovich (CVE-2023-43753) and Majid Shushtarian, Richard Thomaiyar, James Mihm, Vernon Maurey, Nilanthren (CVE-2024-23599).\r\nIntel would like to thank Phoenix Technologies (CVE-2023-43626), Yngweijw (CVE-2024-21871, CVE-2023-42772, CVE-2023-41833, CVE-2024-21829), Jeremy Boone (@uffeux) (CVE-2023-22351, CVE-2023-23904, CVE-2023-25546) for reporting these issues. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-23904', 'title': 'NULL pointer dereference in the UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-43626', 'title': 'Improper access control in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21781', 'title': 'Improper input validation in UEFI firmware for some Intel® Processors may allow a privileged user to enable information disclosure or denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:H/SC:H/SI:N/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23599', 'title': 'Race condition in Seamless Firmware Updates for some Intel® reference platforms may allow a privileged user to potentially enable denial of service via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.9, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21829', 'title': 'Improper input validation in UEFI firmware error handler for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-25546', 'title': 'Out-of-bounds read in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 2.5, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 1.8, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-43753', 'title': 'Improper conditions check in some Intel(R) Processors with Intel® Software Guard Extensions (Intel® SGX) may allow a privileged user to potentially enable information disclosure via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-42772', 'title': 'Untrusted pointer dereference in UEFI firmware for some Intel® reference processors may allow a privileged user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21871', 'title': 'Improper input validation in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-22351', 'title': 'Out-of-bounds write in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-41833', 'title': 'A race condition in UEFI firmware for some Intel® processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2023-41833 | INTEL-SA-01071 | 2024.3 IPU - UEFI Firmware Advisory | Potential security vulnerabilities in UEFI firmware for some Intel® Processors may allow escalation of privilege, denial of service or information disclosure. Intel is releasing UEFI firmware updates to mitigate these potential vulnerabilities. | MEDIUM | 2024-09-10 03:00:00+03:00 | 2024-09-10 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01071.html | cd64f15d2448fcbd005dfd873fb9da33da04b52b5fbd1bd0e14e5af0a8d5e8ba | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in UEFI firmware for some Intel® Processors may allow escalation of privilege, denial of service or information disclosure. Intel is releasing UEFI firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of Intel® Processors update to the latest version provided by the system manufacturer that addresses these issues.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': '2024.3 IPU - UEFI Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01071', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-09-10T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-09-10T00:00:00+00:00', 'initial_release_date': '2024-09-10T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01071.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['The following were found by Intel employees.\xa0 Intel would like to thank Ilya Alexandrovich (CVE-2023-43753) and Majid Shushtarian, Richard Thomaiyar, James Mihm, Vernon Maurey, Nilanthren (CVE-2024-23599).\r\nIntel would like to thank Phoenix Technologies (CVE-2023-43626), Yngweijw (CVE-2024-21871, CVE-2023-42772, CVE-2023-41833, CVE-2024-21829), Jeremy Boone (@uffeux) (CVE-2023-22351, CVE-2023-23904, CVE-2023-25546) for reporting these issues. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-23904', 'title': 'NULL pointer dereference in the UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-43626', 'title': 'Improper access control in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21781', 'title': 'Improper input validation in UEFI firmware for some Intel® Processors may allow a privileged user to enable information disclosure or denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:H/SC:H/SI:N/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23599', 'title': 'Race condition in Seamless Firmware Updates for some Intel® reference platforms may allow a privileged user to potentially enable denial of service via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.9, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21829', 'title': 'Improper input validation in UEFI firmware error handler for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-25546', 'title': 'Out-of-bounds read in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 2.5, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 1.8, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-43753', 'title': 'Improper conditions check in some Intel(R) Processors with Intel® Software Guard Extensions (Intel® SGX) may allow a privileged user to potentially enable information disclosure via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-42772', 'title': 'Untrusted pointer dereference in UEFI firmware for some Intel® reference processors may allow a privileged user to potentially enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-21871', 'title': 'Improper input validation in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-22351', 'title': 'Out-of-bounds write in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-41833', 'title': 'A race condition in UEFI firmware for some Intel® processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-21766 | INTEL-SA-01072 | Intel® oneAPI Math Kernel Library Software Advisory | A potential security vulnerability in some Intel® oneAPI Math Kernel Library software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability. | MEDIUM | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01072.html | c67a9ebbb4789fc06e78786726cd77989c107f17c2dd716954b3ff2debd0c081 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® oneAPI Math Kernel Library software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating Intel® oneAPI Math Kernel Library to version 2024.1 or later.\r\nUpdates are available for download at this location:\r\nhttps://www.intel.com/content/www/us/en/developer/tools/oneapi/onemkl.html#gs.43pz8i\r\n\xa0\r\nIntel recommends updating Intel® Base Toolkit to version 2024.1 or later.\r\nUpdates are available for download at this location:\r\nhttps://www.intel.com/content/www/us/en/developer/tools/oneapi/toolkits.html#base-kit', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® oneAPI Math Kernel Library Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01072', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01072.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank ycdxsb for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-21766', 'title': 'Uncontrolled search path for some Intel® oneAPI Math Kernel Library software before version 2024.1 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-22374 | INTEL-SA-01073 | UPLR1 - Intel® Xeon Processor Advisory | A potential security vulnerability in some Intel® Xeon Processors may allow denial of service. Intel is releasing firmware updates to mitigate this potential vulnerability. | MEDIUM | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01073.html | 57965bce668074a057da17a03d1f1d4ee3f3b4f369d85141ec79e630b3f5332b | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® Xeon Processors may allow denial of service. Intel is releasing firmware updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of Intel® 4th Generation, Intel® 5th Generation and Intel® Xeon® Scalable Processors update to the latest platform provided by the system manufacturer that addresses these issues.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Hardware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Denial of Service', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'UPLR1 - Intel® Xeon Processor Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01073', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01073.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['This issue was found in partnership with an industry partner and Intel employees. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-22374', 'title': 'Insufficient control flow management for some Intel® Xeon Processors may allow an authenticated user to potentially enable denial of service via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-23491 | INTEL-SA-01075 | Intel® Distribution for GDB Software Advisory | Potential security vulnerabilities in some Intel® Distribution for GDB software may allow escalation of privilege or denial of service. Intel is releasing software updates to mitigate this potential vulnerability. | MEDIUM | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01075.html | 0581961aba15ad3c6f7ebe67f2529b6a2d449a2e513b60d39c22e39a7047c4d3 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® Distribution for GDB software may allow escalation of privilege or denial of service. Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating Intel® Distribution for GDB software to version 2024.0.1 or later.\r\nUpdates are available for download at this location:\xa0\r\nhttps://www.intel.com/content/www/us/en/developer/articles/tool/oneapi-standalone-components.html#distributiongdb\r\n\xa0\r\nIntel recommends updating Intel® oneAPI Base Toolkit software to version 2024.1 or later.\r\nUpdates are available for download at this location:\xa0\r\nhttps://www.intel.com/content/www/us/en/developer/tools/oneapi/base-toolkit-download.html', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Distribution for GDB Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01075', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01075.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank ycdxsb (CVE-2024-23491, CVE-2024-23495, CVE-2024-24973), fuzzm3 (CVE-2024-25562) for reporting these issues. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-23491', 'title': 'Uncontrolled search path in some Intel® Distribution for GDB software before version 2024.0.1 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-25562', 'title': 'Improper buffer restrictions in some Intel® Distribution for GDB software before version 2024.0.1 may allow an authenticated user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23495', 'title': 'Incorrect default permissions in some Intel® Distribution for GDB software before version 2024.0.1 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-24973', 'title': 'Improper input validation for some Intel® Distribution for GDB software before version 2024.0.1 may allow an authenticated user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 2.2, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 1, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-25562 | INTEL-SA-01075 | Intel® Distribution for GDB Software Advisory | Potential security vulnerabilities in some Intel® Distribution for GDB software may allow escalation of privilege or denial of service. Intel is releasing software updates to mitigate this potential vulnerability. | MEDIUM | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01075.html | 066e2896dbdaa7fc4b7f5e5d66bf5c47e69be015fa4ca4e40e8541a035e87ee8 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® Distribution for GDB software may allow escalation of privilege or denial of service. Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating Intel® Distribution for GDB software to version 2024.0.1 or later.\r\nUpdates are available for download at this location:\xa0\r\nhttps://www.intel.com/content/www/us/en/developer/articles/tool/oneapi-standalone-components.html#distributiongdb\r\n\xa0\r\nIntel recommends updating Intel® oneAPI Base Toolkit software to version 2024.1 or later.\r\nUpdates are available for download at this location:\xa0\r\nhttps://www.intel.com/content/www/us/en/developer/tools/oneapi/base-toolkit-download.html', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Distribution for GDB Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01075', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01075.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank ycdxsb (CVE-2024-23491, CVE-2024-23495, CVE-2024-24973), fuzzm3 (CVE-2024-25562) for reporting these issues. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-23491', 'title': 'Uncontrolled search path in some Intel® Distribution for GDB software before version 2024.0.1 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-25562', 'title': 'Improper buffer restrictions in some Intel® Distribution for GDB software before version 2024.0.1 may allow an authenticated user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23495', 'title': 'Incorrect default permissions in some Intel® Distribution for GDB software before version 2024.0.1 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-24973', 'title': 'Improper input validation for some Intel® Distribution for GDB software before version 2024.0.1 may allow an authenticated user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 2.2, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 1, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-23495 | INTEL-SA-01075 | Intel® Distribution for GDB Software Advisory | Potential security vulnerabilities in some Intel® Distribution for GDB software may allow escalation of privilege or denial of service. Intel is releasing software updates to mitigate this potential vulnerability. | MEDIUM | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01075.html | 63a046243a6449a89db2e70d535d8628fcf7424e1d65f6e1aab0fefab2d497da | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® Distribution for GDB software may allow escalation of privilege or denial of service. Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating Intel® Distribution for GDB software to version 2024.0.1 or later.\r\nUpdates are available for download at this location:\xa0\r\nhttps://www.intel.com/content/www/us/en/developer/articles/tool/oneapi-standalone-components.html#distributiongdb\r\n\xa0\r\nIntel recommends updating Intel® oneAPI Base Toolkit software to version 2024.1 or later.\r\nUpdates are available for download at this location:\xa0\r\nhttps://www.intel.com/content/www/us/en/developer/tools/oneapi/base-toolkit-download.html', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Distribution for GDB Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01075', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01075.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank ycdxsb (CVE-2024-23491, CVE-2024-23495, CVE-2024-24973), fuzzm3 (CVE-2024-25562) for reporting these issues. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-23491', 'title': 'Uncontrolled search path in some Intel® Distribution for GDB software before version 2024.0.1 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-25562', 'title': 'Improper buffer restrictions in some Intel® Distribution for GDB software before version 2024.0.1 may allow an authenticated user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23495', 'title': 'Incorrect default permissions in some Intel® Distribution for GDB software before version 2024.0.1 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-24973', 'title': 'Improper input validation for some Intel® Distribution for GDB software before version 2024.0.1 may allow an authenticated user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 2.2, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 1, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-24973 | INTEL-SA-01075 | Intel® Distribution for GDB Software Advisory | Potential security vulnerabilities in some Intel® Distribution for GDB software may allow escalation of privilege or denial of service. Intel is releasing software updates to mitigate this potential vulnerability. | MEDIUM | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01075.html | a0c95f2625451721ade8f8b49344e42ddf245e2e39d2f21f7c905858567da613 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® Distribution for GDB software may allow escalation of privilege or denial of service. Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating Intel® Distribution for GDB software to version 2024.0.1 or later.\r\nUpdates are available for download at this location:\xa0\r\nhttps://www.intel.com/content/www/us/en/developer/articles/tool/oneapi-standalone-components.html#distributiongdb\r\n\xa0\r\nIntel recommends updating Intel® oneAPI Base Toolkit software to version 2024.1 or later.\r\nUpdates are available for download at this location:\xa0\r\nhttps://www.intel.com/content/www/us/en/developer/tools/oneapi/base-toolkit-download.html', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Distribution for GDB Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01075', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01075.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank ycdxsb (CVE-2024-23491, CVE-2024-23495, CVE-2024-24973), fuzzm3 (CVE-2024-25562) for reporting these issues. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-23491', 'title': 'Uncontrolled search path in some Intel® Distribution for GDB software before version 2024.0.1 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-25562', 'title': 'Improper buffer restrictions in some Intel® Distribution for GDB software before version 2024.0.1 may allow an authenticated user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23495', 'title': 'Incorrect default permissions in some Intel® Distribution for GDB software before version 2024.0.1 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-24973', 'title': 'Improper input validation for some Intel® Distribution for GDB software before version 2024.0.1 may allow an authenticated user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 2.2, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 1, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-21850 | INTEL-SA-01076 | Intel® TDX Seamldr Software Advisory | A potential security vulnerability in some Intel® TDX Seamldr module software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerabilty. | MEDIUM | 2024-11-12 03:00:00+03:00 | 2024-11-12 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01076.html | 8dee903fb94b08b9772c2b994b87214731776dbfbf6aadb9ba9c702dd47f51fc | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® TDX Seamldr module software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerabilty. ', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating to SEAMLDR version 1.5.02.00, available in Unified Post Launch Release 1 (UPLR1).', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Hardware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® TDX Seamldr Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01076', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-11-12T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-11-12T00:00:00+00:00', 'initial_release_date': '2024-11-12T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01076.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Copyright © Intel Corporation All rights reserved.'}, 'acknowledgments': [{'names': ['This issue was found internally by Intel employees. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-21850', 'cwe': {'id': 'CWE-226', 'name': 'Sensitive Information in Resource Not Removed Before Reuse'}, 'title': 'Sensitive information in resource not removed before reuse in some Intel® TDX Seamldr module software before version 1.5.02.00 may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'HIGH', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.3, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'HIGH', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'NONE', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2023-49144 | INTEL-SA-01078 | UPLR1 - OpenBMC Firmware Advisory | Potential security vulnerabilities in OpenBMC Firmware for some Intel® Server Platforms may allow information disclosure or denial of service. Intel is releasing firmware updates to mitigate these potential vulnerabilities. | MEDIUM | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01078.html | 600687cf5db56245425e9b14ab6bf0343b61c65ed009fd78a28dd36840d37965 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in OpenBMC Firmware for some Intel® Server Platforms may allow information disclosure or denial of service. Intel is releasing firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users update to the latest version provided by the system manufacturer that addresses these issues.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'UPLR1 - OpenBMC Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01078', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01078.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['CVE-2023-49144 was found internally by Intel employees. Intel would like to thank Daniel Medina Velazquez and Thierry Fernandes Faria.\xa0\r\nCVE-2023-35123 was found internally by Intel employees. Intel would like to thank Alexander Gutkin, Cezary Golder and Boris Chernis. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-49144', 'title': 'Out of bounds read in OpenBMC Firmware for some Intel® Server Platforms before versions egs-1.15-0, bhs-0.27 may allow a privileged user to potentially enable information disclosure via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.1, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-35123', 'title': 'Uncaught exception in OpenBMC Firmware for some Intel® Server Platforms before versions egs-1.14-0, bhs-0.27 may allow an authenticated user to potentially enable denial of service via network access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2023-35123 | INTEL-SA-01078 | UPLR1 - OpenBMC Firmware Advisory | Potential security vulnerabilities in OpenBMC Firmware for some Intel® Server Platforms may allow information disclosure or denial of service. Intel is releasing firmware updates to mitigate these potential vulnerabilities. | MEDIUM | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01078.html | eaf829648d3b5cf05e99fd2221bd545397799135fcb4ba35f35960729ce0936d | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in OpenBMC Firmware for some Intel® Server Platforms may allow information disclosure or denial of service. Intel is releasing firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users update to the latest version provided by the system manufacturer that addresses these issues.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'UPLR1 - OpenBMC Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01078', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01078.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['CVE-2023-49144 was found internally by Intel employees. Intel would like to thank Daniel Medina Velazquez and Thierry Fernandes Faria.\xa0\r\nCVE-2023-35123 was found internally by Intel employees. Intel would like to thank Alexander Gutkin, Cezary Golder and Boris Chernis. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-49144', 'title': 'Out of bounds read in OpenBMC Firmware for some Intel® Server Platforms before versions egs-1.15-0, bhs-0.27 may allow a privileged user to potentially enable information disclosure via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.1, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-35123', 'title': 'Uncaught exception in OpenBMC Firmware for some Intel® Server Platforms before versions egs-1.14-0, bhs-0.27 may allow an authenticated user to potentially enable denial of service via network access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-21820 | INTEL-SA-01079 | Intel® Xeon® Processor with Intel® SGX Advisory | Potential security vulnerabilities in some Intel® Xeon® processors using Intel® Software Guard Extensions (Intel SGX) may allow escalation of privilege. Intel is releasing firmware updates to mitigate these potential vulnerabilities. | HIGH | 2024-11-12 03:00:00+03:00 | 2024-11-12 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01079.html | aace0d03075cb9cbaf54a4c504e99054c735af34fa3f75c7e933abe46ee9dfd5 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® Xeon® processors using Intel® Software Guard Extensions (Intel SGX) may allow escalation of privilege. Intel is releasing firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of the Intel® SGX module update to the latest version provided by the system manufacturer that addresses this issue.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Hardware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Xeon® Processor with Intel® SGX Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01079', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-11-12T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-11-12T00:00:00+00:00', 'initial_release_date': '2024-11-12T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01079.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Copyright © Intel Corporation All rights reserved.'}, 'acknowledgments': [{'names': ['This issue was found internally by Intel. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-21820', 'cwe': {'id': 'CWE-276', 'name': 'Incorrect Default Permissions'}, 'title': 'Incorrect default permissions in some Intel® Xeon® processor memory controller configurations when using Intel® SGX may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 7.2, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'availabilityImpact': 'NONE', 'privilegesRequired': 'HIGH', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.5, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'privilegesRequired': 'HIGH', 'subIntegrityImpact': 'HIGH', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'NONE', 'subConfidentialityImpact': 'HIGH', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23918', 'cwe': {'id': 'CWE-754', 'name': 'Improper Check for Unusual or Exceptional Conditions'}, 'title': 'Improper conditions check in some Intel® Xeon® processor memory controller configurations when using Intel® SGX may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'HIGH', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'HIGH', 'vulnAvailabilityImpact': 'HIGH', 'subConfidentialityImpact': 'HIGH', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-23918 | INTEL-SA-01079 | Intel® Xeon® Processor with Intel® SGX Advisory | Potential security vulnerabilities in some Intel® Xeon® processors using Intel® Software Guard Extensions (Intel SGX) may allow escalation of privilege. Intel is releasing firmware updates to mitigate these potential vulnerabilities. | HIGH | 2024-11-12 03:00:00+03:00 | 2024-11-12 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01079.html | b68096d7e820ab0926fbc9856feabecc1b9615982a36fb9648f4089ffbcf7b95 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® Xeon® processors using Intel® Software Guard Extensions (Intel SGX) may allow escalation of privilege. Intel is releasing firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of the Intel® SGX module update to the latest version provided by the system manufacturer that addresses this issue.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Hardware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Xeon® Processor with Intel® SGX Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01079', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-11-12T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-11-12T00:00:00+00:00', 'initial_release_date': '2024-11-12T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01079.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Copyright © Intel Corporation All rights reserved.'}, 'acknowledgments': [{'names': ['This issue was found internally by Intel. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-21820', 'cwe': {'id': 'CWE-276', 'name': 'Incorrect Default Permissions'}, 'title': 'Incorrect default permissions in some Intel® Xeon® processor memory controller configurations when using Intel® SGX may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 7.2, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'availabilityImpact': 'NONE', 'privilegesRequired': 'HIGH', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.5, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'privilegesRequired': 'HIGH', 'subIntegrityImpact': 'HIGH', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'NONE', 'subConfidentialityImpact': 'HIGH', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-23918', 'cwe': {'id': 'CWE-754', 'name': 'Improper Check for Unusual or Exceptional Conditions'}, 'title': 'Improper conditions check in some Intel® Xeon® processor memory controller configurations when using Intel® SGX may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'HIGH', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'HIGH', 'vulnAvailabilityImpact': 'HIGH', 'subConfidentialityImpact': 'HIGH', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-24853 | INTEL-SA-01083 | 2024.3 IPU - SMI Transfer Monitor Advisory | A potential security vulnerability in SMI Transfer monitor (STM) may allow escalation of privilege. Intel is releasing microcode updates to mitigate this potential vulnerability. | HIGH | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01083.html | 37545b094a8610b3dc52622762024846b975e3f4a41f8478b4be171a03e10707 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in SMI Transfer monitor (STM) may allow escalation of privilege. Intel is releasing microcode updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of affected Intel® Processors update to the latest firmware provided by the system manufacturer that addresses this issue.\r\nIntel has released microcode update for the affected products that are currently supported on the public github repository.\r\nPlease see details below on access to the microcode:Public Github: \xa0https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files.\r\nThe microcode patch can be OS loaded.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Hardware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': '2024.3 IPU - SMI Transfer Monitor Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01083', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01083.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['This issue was discovered internally by Intel employees. Intel would like to thank Ezra Caltum for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-24853', 'title': 'Incorrect behavior order in transition between executive monitor and SMI transfer monitor (STM) in some Intel® Processor may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-25565 | INTEL-SA-01085 | Intel® UEFI Firmware Advisory | A potential security vulnerability in UEFI firmware for some Intel® Xeon® Processors may allow denial of service. Intel is releasing firmware updates to mitigate this potential vulnerability. | LOW | 2024-11-12 03:00:00+03:00 | 2024-11-12 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01085.html | 9c8460cfd816d6f2d1a0d0147f464b1f2aac50560269b29da7700c31788afb2f | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in UEFI firmware for some Intel® Xeon® Processors may allow denial of service. Intel is releasing firmware updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of 4th and 5th Generation Intel® Xeon® Scalable Processors update to the latest version provided by the system manufacturer that addresses these issues.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Low', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Denial of Service', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® UEFI Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01085', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-11-12T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-11-12T00:00:00+00:00', 'initial_release_date': '2024-11-12T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01085.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Copyright © Intel Corporation All rights reserved.'}, 'acknowledgments': [{'names': ['This issue was found internally by Intel employees. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-25565', 'cwe': {'id': 'CWE-691', 'name': 'Insufficient Control Flow Management'}, 'title': 'Insufficient control flow management in UEFI firmware for some Intel® Xeon® Processors may allow an authenticated user to enable denial of service via local access. ', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 3.8, 'attackVector': 'LOCAL', 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'cvss_v4': {'version': '4.0', 'baseScore': 4.8, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'NONE', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'LOW', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'NONE'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-25576 | INTEL-SA-01087 | Intel Agilex® FPGA Firmware Advisory | A potential security vulnerability in some Intel Agilex® FPGA Firmware may allow escalation of privilege. Intel is releasing firmrware updates to mitigate this potential vulnerability. | HIGH | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01087.html | 63cdaaa41a9077b82f2e424321bdd04ff0f50142c54527d912862ad7a3cd62b3 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel Agilex® FPGA Firmware may allow escalation of privilege. Intel is releasing firmrware updates to mitigate this potential vulnerability. ', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating Intel Agilex® FPGA 7 FPGA firmware to version 24.1 or later.\r\nUpdates are available for download at this location:\xa0FPGA software', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel Agilex® FPGA Firmware Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01087', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01087.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['This issue was found internally by Intel. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-25576', 'title': 'improper access control in firmware for some Intel(R) FPGA products before version 24.1 may allow a privileged user to enable escalation of privilege via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.9, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-23974 | INTEL-SA-01088 | Intel® ISH Software Installer Advisory | A potential security vulnerability in some Intel® Integrated Sensor Hub (ISH) software installers may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability. | MEDIUM | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01088.html | 1d018797be59f35a1873b24fe224f3fd40dbe3e44d087396d123c15efb017e4d | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® Integrated Sensor Hub (ISH) software installers may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of Intel® ISH software installers for Intel® Core™ Processor Family update to the latest version provided by the system manufacturer that addresses these issues. \xa0\r\nUpdates for NUC are available for download at these locations:\r\nIntel® NUC M15 Laptop Kits LAPBC710 and LAPBC510:\r\nhttps://www.intel.com/content/www/us/en/download/19731\r\nIntel® NUC M15 Laptop Kits LAPRC710 and LAPRC510:\r\nhttps://www.intel.com/content/www/us/en/download/736480\r\nProduct support for many NUC products has moved to ASUS. Technical and Warranty Support for Intel’s NUC 7 through NUC 13 Systems has transitioned to ASUS as of January 16, 2024. See the NUC Customer Support notice\xa0for more information.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® ISH Software Installer Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01088', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01088.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['This issue was found internally by Intel. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-23974', 'title': 'Incorrect default permissions in some Intel® ISH software installers may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-25561 | INTEL-SA-01089 | Intel® HID Event Filter Software Installer Advisory | A potential security vulnerability in some Intel® Human Interface Device (HID) Event Filter software installers may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability. | MEDIUM | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01089.html | 0871e9361580d067585d8b2fa6273bffb2fe3d2610c08f9cf727868ca97813b9 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® Human Interface Device (HID) Event Filter software installers may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of Intel® HID Event Filter software installers update to the latest version provided by the system manufacturer that addresses these issues.Updates are available for Intel® NUC M15 or X15 Laptop Kits at this download location:https://www.intel.com/content/www/us/en/download/19820Product support for many NUC products has moved to ASUS. Technical and Warranty Support for Intel's NUC 7 through NUC 13 Systems has transitioned to ASUS as of January 16, 2024.\xa0See the\xa0NUC Customer Support notice\xa0for more information.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® HID Event Filter Software Installer Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01089', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01089.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank hamdi @falconCorrup and Mohamed amine saidani for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-25561', 'title': 'Insecure inherited permissions in some Intel® HID Event Filter software installers before version 2.2.2.1 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-24580 | INTEL-SA-01094 | Intel® Data Center GPU Max Series Advisory | A potential security vulnerability in some Intel® Data Center GPU Max Series 1100 and 1550 products may allow denial of service. Intel is releasing prescriptive guidance to address this potential vulnerability. | MEDIUM | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01094.html | 31deda634f460d9852e6592b65db2d296ca7ea0484e098097fc53a352a3bb9e2 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® Data Center GPU Max Series 1100 and 1550 products may allow denial of service. Intel is releasing prescriptive guidance to address this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends users follow existing security best practices and alternate security controls, including:Intel® Data Center GPU Max Series 1100 and 1550\xa0Intel(r) Data Center GPU Max Configuration Recommendation.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Hardware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Denial of Service', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Data Center GPU Max Series Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01094', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01094.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['This issue was found internally by Intel employees. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-24580', 'title': 'Improper conditions check in some Intel® Data Center GPU Max Series 1100 and 1550 products may allow a privileged user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-22378 | INTEL-SA-01095 | Intel Unite® Client Software Installer Advisory | A potential security vulnerability in some Intel Unite® Client software installers may allow escalation of privilege. Intel is not releasing updates to mitigate this potential vulnerability and has issued a Product Discontinuation Notice for Intel Unite® Client software. | MEDIUM | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01095.html | 97a36f6169ca1e5091e87b19868540679d3d6aa92810f8649fddd0be2529fedf | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel Unite® Client software installers may allow escalation of privilege. Intel is not releasing updates to mitigate this potential vulnerability and has issued a Product Discontinuation Notice for Intel Unite® Client software.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel has issued a\xa0Product Discontinuation Notice\xa0for Intel Unite® Client software and recommends that users of the Intel Unite® software uninstall it or discontinue use at their earliest convenience.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel Unite® Client Software Installer Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01095', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01095.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank ycdxsb and @sim0nsecurity for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-22378', 'title': 'Incorrect default permissions in some Intel Unite® Client Extended Display Plugin software installers before version 1.1.352.157 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-24968 | INTEL-SA-01097 | 2024.3 IPU - Intel® Processor Advisory | A potential security vulnerability in some Intel® Processors may allow denial of service. Intel is releasing firmware updates to mitigate this potential vulnerability. | MEDIUM | 2024-09-10 03:00:00+03:00 | 2024-09-10 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01097.html | cbdeeddb8e7ad03362913eaf383944ae6a7ee9ec8555b6ff3245e4abd2cd6d2d | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® Processors may allow denial of service. Intel is releasing firmware updates to mitigate this potential vulnerability. ', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updated microcode to the latest version provided by your system manufacturer.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Hardware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Denial of Service', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': '2024.3 IPU - Intel® Processor Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01097', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-09-10T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-09-10T00:00:00+00:00', 'initial_release_date': '2024-09-10T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01097.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['This issue was found internally by Intel employees. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-24968', 'title': 'Improper finite state machines (FSMs) in hardware logic in some Intel® Processors may allow an privileged user to potentially enable a denial of service via local access. ', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.6, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-27457 | INTEL-SA-01099 | Intel® TDX Module Software Advisory | A potential security vulnerability in Intel® Trust Domain Extensions (TDX) Module firmware may allow information disclosure. Intel is releasing firmware updates to mitigate this potential vulnerability. | LOW | 2024-10-08 03:00:00+03:00 | 2024-10-08 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01099.html | 2b8ddd579136bf28b20eb5b4996e343ec8a36bb5e0982a33b20582bfacce1659 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in Intel® Trust Domain Extensions (TDX) Module firmware may allow information disclosure. Intel is releasing firmware updates to mitigate this potential vulnerability. ', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of the Intel® TDX module update to the latest version provided by the system manufacturer that addresses this issue.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Low', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Hardware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® TDX Module Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01099', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-10-08T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-10-08T00:00:00+00:00', 'initial_release_date': '2024-10-08T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01099.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Copyright © Intel Corporation All rights reserved.'}, 'acknowledgments': [{'names': ['Intel would like to thank Luka Wilke,\xa0 Florian Sieck, and Thomas Eisenbarth from the University of Lübeck for reporting this issue to Intel. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-27457', 'cwe': {'id': 'CWE-754', 'name': 'Improper Check for Unusual or Exceptional Conditions'}, 'title': 'Improper check for unusual or exceptional conditions in Intel® TDX Module firmware before version 1.5.06 may allow a privileged user to potentially enable information disclosure via local access. ', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 2.5, 'attackVector': 'LOCAL', 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'availabilityImpact': 'NONE', 'privilegesRequired': 'HIGH', 'confidentialityImpact': 'LOW'}, 'cvss_v4': {'version': '4.0', 'baseScore': 1.8, 'attackVector': 'LOCAL', 'baseSeverity': 'LOW', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'attackRequirements': 'NONE', 'privilegesRequired': 'HIGH', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'NONE', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'NONE', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'LOW'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-24980 | INTEL-SA-01100 | 2024.3 IPU - Intel® Xeon® Processor Advisory | A potential security vulnerability in some 3rd, 4th, and 5th Generation Intel® Xeon® Processors may allow escalation of privilege. Intel is releasing firmware updates to mitigate this potential vulnerability. | MEDIUM | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01100.html | 79c504683c15b23b4400f148748473937f390a7e2f55cf173e7630de0ffc4979 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some 3rd, 4th, and 5th Generation Intel® Xeon® Processors may allow escalation of privilege. Intel is releasing firmware updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of Intel® 3rd, 4th and 5th Generation Intel® Xeon® Scalable Processors update to the latest version provided by the system manufacturer that addresses these issues.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Hardware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': '2024.3 IPU - Intel® Xeon® Processor Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01100', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01100.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['This issue was found internally by Intel employees. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-24980', 'title': ' Protection mechanism failure in some 3rd, 4th, and 5th Generation Intel® Xeon® Processors may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:H/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:L/SI:H/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-21853 | INTEL-SA-01101 | Intel® Xeon® Processor Advisory | A potential security vulnerability in some 4th and 5th Generation Intel® Xeon® Processors may allow denial of service. Intel is releasing microcode updates to mitigate this potential vulnerability. | MEDIUM | 2024-11-12 03:00:00+03:00 | 2024-11-12 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01101.html | 800b8d7233d0fb658343b600c5bd82432599f1b8d8e3ff28a2daa65d3640ff2c | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some 4th and 5th Generation Intel® Xeon® Processors may allow denial of service. Intel is releasing microcode updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating 4th and 5th Generation Intel® Xeon® Scalable Processors with the latest firmware provided by the OEM.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Hardware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Denial of Service', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Xeon® Processor Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01101', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-11-12T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-11-12T00:00:00+00:00', 'initial_release_date': '2024-11-12T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01101.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Copyright © Intel Corporation All rights reserved.'}, 'acknowledgments': [{'names': ['This issue was found internally by Intel employees. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-21853', 'cwe': {'id': 'CWE-1245', 'name': 'Improper Finite State Machines (FSMs) in Hardware Logic'}, 'title': 'Faulty finite state machines (FSMs) in the hardware logic in some 4th and 5th Generation Intel® Xeon® Processors may allow an authorized user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 4.7, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.7, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'attackRequirements': 'NONE', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'NONE', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'HIGH', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'NONE'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2023-43747 | INTEL-SA-01102 | Intel® Connectivity Performance Suite Software Installer Advisory | A potential security vulnerability in some Intel® Connectivity Performance Suite software installers may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability. | MEDIUM | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01102.html | 20923a1c9eacf6057a5c1dd371335898b7d27230ec7e9abd76c089118b1ab2c4 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® Connectivity Performance Suite software installers may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating Intel® Connectivity Performance Suite software to version 30.24.144 or later.\r\nUpdates are available for download at this location:\xa0\r\nhttps://www.intel.com/content/www/us/en/download/738623', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Connectivity Performance Suite Software Installer Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01102', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01102.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank Mohamed amine saidani for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-43747', 'title': 'Incorrect default permissions for some Intel® Connectivity Performance Suite software installers before version 2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-23984 | INTEL-SA-01103 | 2024.3 IPU - Intel® Processor RAPL Interface Advisory | A potential security vulnerability in the Running Average Power Limit (RAPL) interface for some Intel® Processors may allow information disclosure. Intel is releasing firmware updates to mitigate this potential vulnerability. | MEDIUM | 2024-09-10 03:00:00+03:00 | 2024-09-10 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01103.html | dca52ac55ed8276f62a9af68be1c4499ae819b471fd82a9b3fa52ff13cda03a5 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in the Running Average Power Limit (RAPL) interface for some Intel® Processors may allow information disclosure. Intel is releasing firmware updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of some Intel® Processor RAPL interfaces update to the latest firmware version provided by the system manufacturer that addresses these issues.\r\nFor additional information or guidance about the RAPL issue please see the RAPL guidance: Running Average Power Limit Energy Reporting', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Hardware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': '2024.3 IPU - Intel® Processor RAPL Interface Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01103', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-09-10T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-09-10T00:00:00+00:00', 'initial_release_date': '2024-09-10T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01103.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['This issue was found by Intel employees. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-23984', 'title': 'Observable discrepancy in RAPL interface for some Intel® Processors may allow a privileged user to potentially enable information disclosure via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-23909 | INTEL-SA-01104 | Intel® FPGA SDK for OpenCL™ Software Technology Advisory | A potential security vulnerability in some Intel® FPGA SDK for OpenCL™ software technology may allow escalation of privilege. Intel is not releasing updates to mitigate this potential vulnerability and has issued a Product Discontinuation Notice for Intel® FPGA SDK for OpenCL™ software technology. | MEDIUM | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01104.html | 1fefb69c78835b56301480fd0d960490cca46726c764910c648476d7f72ce485 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® FPGA SDK for OpenCL™ software technology may allow escalation of privilege. Intel is not releasing updates to mitigate this potential vulnerability and has issued a Product Discontinuation Notice for Intel® FPGA SDK for OpenCL™ software technology.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel has issued a product discontinuation notice for Intel® FPGA SDK for OpenCL™ software technology and recommends that users of the Intel® FPGA SDK for OpenCL™ software technology migrate to Intel® FPGA Add-on for oneAPI Base Toolkit at their earliest convenience.\r\nUpdates are available for download at this location:\r\nIntel® FPGA Add-on for oneAPI Base Toolkit:https://www.intel.com/content/www/us/en/developer/tools/oneapi/fpga.html', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® FPGA SDK for OpenCL™ Software Technology Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01104', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01104.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank ycdxsb for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-23909', 'title': 'Uncontrolled search path in some Intel® FPGA SDK for OpenCL™ software technology may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-28046 | INTEL-SA-01105 | Intel® GPA Software Advisory | A potential security vulnerability in some Intel® Graphics Performance Analyzers (Intel® GPA) software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability. | MEDIUM | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01105.html | e280562c4faa8bb70937552bce5e896104db611172ed29b0a77e0d28883b2b35 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® Graphics Performance Analyzers (Intel® GPA) software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating Intel® GPA software to version 2024.1 or later.\r\nUpdates are available for download at this location:\r\nhttps://www.intel.com/content/www/us/en/developer/tools/graphics-performance-analyzers/download.html', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® GPA Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01105', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01105.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank Mohamed amine Saidani for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-28046', 'title': 'Uncontrolled search path in some Intel® GPA software before version 2024.1 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-22376 | INTEL-SA-01106 | Intel® Ethernet Adapter Driver Pack Software Installer Advisory | A potential security vulnerability in some Intel® Ethernet Adapter Driver Pack software installers may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability. | MEDIUM | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01106.html | 0aba5ebec67f8a850bcfd921339e32dedd3278bb060fb6cb28a2ff55b8ce278e | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® Ethernet Adapter Driver Pack software installers may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating Intel® Ethernet Adapter Complete Driver Pack software to version 28.3 or later.\r\nUpdates are available for download at this location:\xa0https://www.intel.com/content/www/us/en/download/15084/intel-ethernet-adapter-complete-driver-pack.html', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Ethernet Adapter Driver Pack Software Installer Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01106', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01106.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank Mohamed amine saidani for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-22376', 'title': 'Uncontrolled search path element in some installation software for Intel® Ethernet Adapter Driver Pack before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-23908 | INTEL-SA-01107 | Flexlm License Daemons for Intel® FPGA Software Advisory | A potential security vulnerability in some Flexlm License Daemons for Intel® FPGA may allow escalation of privilege. Intel is releasing updates to mitigate this potential vulnerability. | MEDIUM | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01107.html | ad82359c60d2b2bb4ed39f82ef33916a9138974c183781d921a59bf6d2766388 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Flexlm License Daemons for Intel® FPGA may allow escalation of privilege. Intel is releasing updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating Flexlm License Daemons for Intel® FPGA Software to version v11.19.5.0 later.\r\nUpdates are available for download at this location:\xa0https://www.intel.com/content/www/us/en/software-kit/709649/flexlm-license-daemons-for-intel-fpga-software.html', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Flexlm License Daemons for Intel® FPGA Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01107', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01107.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank Falcon Corruption @falconCorrup for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-23908', 'title': 'Insecure inherited permissions in some Flexlm License Daemons for Intel® FPGA software before version v11.19.5.0 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-26025 | INTEL-SA-01110 | Intel® Advisor Software Advisory | A potential security vulnerability in some Intel® Advisor software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability. | MEDIUM | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01110.html | 37facb4fdd01e501fa72e496ca0ccb62556c05773b3eb44551c429377dc15dc7 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® Advisor software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating Intel® Advisor to version 2024.1 or later.\r\nUpdates are available for download at this location:\xa0\r\nhttps://www.intel.com/content/www/us/en/developer/articles/tool/oneapi-standalone-components.html#advisor\r\n\xa0\r\nIntel recommends updating Intel® oneAPI Base Toolkit to version 2024.1 or later.\r\nUpdates are available for download at this location:\xa0\r\nhttps://www.intel.com/content/www/us/en/developer/tools/oneapi/toolkits.html#base-kit', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Advisor Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01110', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01110.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank ycdxsb for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-26025', 'title': 'Incorrect default permissions for some Intel® Advisor software before version 2024.1 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-24985 | INTEL-SA-01111 | Intel® ACTM Module Software Advisory | Potential security vulnerabilities in some Intel® processors with Intel® Alias Checking Trusted Module (Intel® ACTM) may allow escalation of privilege. Intel is releasing firmware updates to mitigate these potential vulnerabilities. | HIGH | 2024-11-12 03:00:00+03:00 | 2024-11-12 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01111.html | 42bf54e1a17b31c307ce57c78e74c244ebf0c6ac2e9699fd43f8e7d10e92a65d | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® processors with Intel® Alias Checking Trusted Module (Intel® ACTM) may allow escalation of privilege. Intel is releasing firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of the Intel® ACTM module update to the latest version provided by the system manufacturer that addresses this issue.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Hardware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® ACTM Module Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01111', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-11-12T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-11-12T00:00:00+00:00', 'initial_release_date': '2024-11-12T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01111.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Copyright © Intel Corporation All rights reserved.'}, 'acknowledgments': [{'names': ['These issues were found internally by Intel. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-24985', 'cwe': {'id': 'CWE-668', 'name': 'Exposure of Resource to Wrong Sphere'}, 'title': 'Exposure of resource to wrong sphere in some Intel® processors with Intel® ACTM may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 7.2, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'availabilityImpact': 'NONE', 'privilegesRequired': 'HIGH', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.5, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'privilegesRequired': 'HIGH', 'subIntegrityImpact': 'HIGH', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'NONE', 'subConfidentialityImpact': 'HIGH', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-22185', 'cwe': {'id': 'CWE-367', 'name': 'Time-of-check Time-of-use (TOCTOU) Race Condition'}, 'title': 'Time-of-check Time-of-use Race Condition in some Intel® processors with Intel® ACTM may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 7.2, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'availabilityImpact': 'NONE', 'privilegesRequired': 'HIGH', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.5, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'privilegesRequired': 'HIGH', 'subIntegrityImpact': 'HIGH', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'NONE', 'subConfidentialityImpact': 'HIGH', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-22185 | INTEL-SA-01111 | Intel® ACTM Module Software Advisory | Potential security vulnerabilities in some Intel® processors with Intel® Alias Checking Trusted Module (Intel® ACTM) may allow escalation of privilege. Intel is releasing firmware updates to mitigate these potential vulnerabilities. | HIGH | 2024-11-12 03:00:00+03:00 | 2024-11-12 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01111.html | 864bc8d3a47d5c10ff4d18ec941a4efb6162133688645f5c958cd730a0f21e67 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Potential security vulnerabilities in some Intel® processors with Intel® Alias Checking Trusted Module (Intel® ACTM) may allow escalation of privilege. Intel is releasing firmware updates to mitigate these potential vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of the Intel® ACTM module update to the latest version provided by the system manufacturer that addresses this issue.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Hardware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® ACTM Module Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01111', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-11-12T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-11-12T00:00:00+00:00', 'initial_release_date': '2024-11-12T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01111.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Copyright © Intel Corporation All rights reserved.'}, 'acknowledgments': [{'names': ['These issues were found internally by Intel. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-24985', 'cwe': {'id': 'CWE-668', 'name': 'Exposure of Resource to Wrong Sphere'}, 'title': 'Exposure of resource to wrong sphere in some Intel® processors with Intel® ACTM may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 7.2, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'availabilityImpact': 'NONE', 'privilegesRequired': 'HIGH', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.5, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'privilegesRequired': 'HIGH', 'subIntegrityImpact': 'HIGH', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'NONE', 'subConfidentialityImpact': 'HIGH', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-22185', 'cwe': {'id': 'CWE-367', 'name': 'Time-of-check Time-of-use (TOCTOU) Race Condition'}, 'title': 'Time-of-check Time-of-use Race Condition in some Intel® processors with Intel® ACTM may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 7.2, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'availabilityImpact': 'NONE', 'privilegesRequired': 'HIGH', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 8.5, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'privilegesRequired': 'HIGH', 'subIntegrityImpact': 'HIGH', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'NONE', 'subConfidentialityImpact': 'HIGH', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2023-43489 | INTEL-SA-01112 | Intel® CIP Software Advisory | A potential security vulnerability in some Intel® Computing Improvement Program (Intel® CIP) may allow denial of service. Intel is releasing software updates to mitigate this potential vulnerability. | MEDIUM | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01112.html | 6373b04bf0b3dd55df508b1381ab07b11bd10cf04210fe9517e68263771adb76 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® Computing Improvement Program (Intel® CIP) may allow denial of service. Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating Intel® CIP software to version 2.4.10717 \xa0or later.\r\nUpdates are available for download at this location:\r\nhttps://www.intel.com/content/www/us/en/support/topics/idsa-cip.html', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Denial of Service', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® CIP Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01112', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01112.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank ycdxsb for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2023-43489', 'title': 'Improper access control for some Intel® CIP software before version 2.4.10717 may allow an authenticated user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.8, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-23907 | INTEL-SA-01113 | Intel® High Level Synthesis Compiler Software Advisory | A potential security vulnerability in some Intel® High Level Synthesis Compiler software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability. | MEDIUM | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01113.html | 91c0f4d1e97a5aecab62849b4698ba2bfb91eda1c93a968afd46905c3e972f13 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® High Level Synthesis Compiler software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating Intel® High Level Synthesis Compiler to version 23.4 or later.\r\nUpdates are available for download at this location:\r\nhttps://cdrdv2.intel.com/v1/dl/getContent/794625/794651?filename=HLSProSetup-23.4.0.79-windows.exe\r\n\xa0\r\nIntel recommends updating Intel® Quartus® Prime Pro Edition Design Software to version 23.4 or later.\r\nUpdates are available for download at this location:\r\nhttps://www.intel.com/content/www/us/en/software-kit/794624/intel-quartus-prime-pro-edition-design-software-version-23-4-for-linux.html\r\n\xa0\r\nIntel recommends updating Intel® DPC++ C++ Compiler software to version 2024.1 or later.\r\nUpdates are available for download at this location:\r\nhttps://www.intel.com/content/www/us/en/developer/articles/tool/oneapi-standalone-components.html#dpcpp-cpp', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® High Level Synthesis Compiler Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01113', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01113.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank ycdxsb for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-23907', 'title': 'Uncontrolled search path in some Intel® High Level Synthesis Compiler software before version 23.4 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-21784 | INTEL-SA-01114 | Intel® IPP Cryptography Software Advisory | A potential security vulnerability in some Intel® Integrated Performance Primitives Cryptography (Intel® IPP Cryptography) software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability. | MEDIUM | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01114.html | d271402ea7f24ac84cd67e70a8e9471a91112ff6ab3b8f9b5b9647f9da730dfe | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® Integrated Performance Primitives Cryptography (Intel® IPP Cryptography) software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating Intel® Integrated Performance Primitives Cryptography software to version 2021.11 or later.\r\nUpdates are available for download at this location:\r\nhttps://www.intel.com/content/www/us/en/docs/ipp-crypto/developer-guide-reference/2021-9/overview.html\r\n\xa0\r\nIntel recommends updating Intel® oneAPI Base Toolkit to version 2024.1 or later.\r\nUpdates are available for download at this location:\r\nhttps://www.intel.com/content/www/us/en/developer/tools/oneapi/toolkits.html#base-kit', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® IPP Cryptography Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01114', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01114.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank ycdxsb for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-21784', 'title': 'Uncontrolled search path for some Intel® IPP Cryptography software before version 2021.11 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-28876 | INTEL-SA-01115 | Intel® MPI Library Software Advisory | A potential security vulnerability in some Intel® MPI Library software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability. | MEDIUM | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01115.html | 2ca375bc49e585ac0def3c840ce572880944f14f2533f8be919d4619b5472b95 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® MPI Library software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating Intel® MPI Library software to version 2021.12 or later.\xa0\r\nUpdates are available for download at this location:\r\nhttps://www.intel.com/content/www/us/en/developer/articles/tool/oneapi-standalone-components.html#mpi\r\n\xa0\r\nIntel recommends updating Intel® oneAPI HPC Toolkit to version 2024.1 or later.\r\nUpdates are available for download at this location:\r\nhttps://www.intel.com/content/www/us/en/developer/tools/oneapi/toolkits.html#hpc-kit', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® MPI Library Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01115', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01115.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank ycdxsb for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-28876', 'title': 'Uncontrolled search path for some Intel® MPI Library software before version 2021.12 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-26027 | INTEL-SA-01116 | Intel® Simics Package Manager Software Advisory | A potential security vulnerability in some Intel® Simics Package Manager software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability. | MEDIUM | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01116.html | e36256a0763f2d6ad2efac5558b78dec4a240f7757df956c220b63f00e8aaa95 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® Simics Package Manager software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of Intel® Simics Package Manager software update to 1.8.3 or later.\r\nUpdates are available for download at this location:\xa0\r\nhttps://lemcenter.intel.com/productDownload/?Product=256660e5-a404-4390-b436-f64324d94959', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Simics Package Manager Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01116', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01116.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank Mohamed amine saidani for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-26027', 'title': 'Uncontrolled search path for some Intel® Simics Package Manager software before version 1.8.3 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-28172 | INTEL-SA-01117 | Intel® Trace Analyzer and Collector Software Advisory | A potential security vulnerability in some Intel® Trace Analyzer and Collector software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability. | MEDIUM | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01117.html | da98e47e16cf7895d529cf19f9ba4fa1f6f0b94c6ef50a0d4319e8e79a3b2620 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® Trace Analyzer and Collector software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of Intel® Trace Analyzer and Collector software update to 2022.1 or later.\r\nUpdates are available for download at this location:\r\nhttps://www.intel.com/content/www/us/en/developer/articles/tool/oneapi-standalone-components.html#trace', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Trace Analyzer and Collector Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01117', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01117.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank ycdxsb for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-28172', 'title': 'Uncontrolled search path for some Intel® Trace Analyzer and Collector software before version 2022.1 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-25939 | INTEL-SA-01118 | 3rd Generation Intel® Xeon® Scalable Processor Advisory | A potential security vulnerability in some 3rd Generation Intel® Xeon® Scalable Processors may allow denial of service. Intel is releasing microcode updates to mitigate this potential vulnerability. | MEDIUM | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01118.html | f21ce4106ffc2f4c21469f3f7c7fe8372322fa336271730cc7050afd79d213e6 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some 3rd Generation Intel® Xeon® Scalable Processors may allow denial of service. Intel is releasing microcode updates to mitigate this potential vulnerability. ', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends that users of 3rd Generation Intel® Xeon® Scalable Processors update to the latest microcode version provided by the system manufacturer that addresses these issues.', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Hardware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Denial of Service', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': '3rd Generation Intel® Xeon® Scalable Processor Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01118', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01118.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['This issue was found internally by Intel employees. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-25939', 'title': 'Mirrored regions with different values in 3rd Generation Intel® Xeon® Scalable Processors may allow a privileged user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-28947 | INTEL-SA-01121 | Intel® Server Board S2600ST Family Firmware Advisory | A potential security vulnerability in some Intel® Server Board S2600ST Family firmware may allow escalation of privilege. Intel is releasing software pdates to mitigate this potential vulnerability. | HIGH | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01121.html | fba8648b041cd545ae1cb778d03840e25d6fb28bdc302ae31f7df811fc61ba21 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® Server Board S2600ST Family firmware may allow escalation of privilege. Intel is releasing software pdates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating Intel® Server Board S2600ST Family firmware to version 02.01.0017 or later.\xa0\r\nUpdates are available for download at this location:\xa0\r\nhttps://www.intel.com/content/www/us/en/download/19139', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Firmware', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® Server Board S2600ST Family Firmware Advisory ', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01121', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01121.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank Eason and vul_pwner for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-28947', 'title': 'Improper input validation in kernel mode driver for some Intel® Server Board S2600ST Family firmware before version 02.01.0017 may allow a privileged user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7.1, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-29015 | INTEL-SA-01122 | Intel® VTune™ Profiler Software Advisory | A potential security vulnerability in some Intel® VTune™ Profiler software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability. | MEDIUM | 2024-08-13 03:00:00+03:00 | 2024-08-13 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01122.html | c44dc3ceb525c877cbb44ddf11b91249eb4502a4eaa32b43a59f6b38908f527a | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerability in some Intel® VTune™ Profiler software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel® recommends updating Intel® oneAPI Base Toolkits to version 2024.1 or laterUpdates are available for download at this location:\xa0https://www.intel.com/content/www/us/en/developer/tools/oneapi/base-toolkit-download.html\xa0\r\nIntel® recommends updating VTune Profiler to version VTune 2024.1 or later.\r\nUpdates are available for download at this location:\xa0https://www.intel.com/content/www/us/en/developer/articles/tool/oneapi-standalone-components.html#vtune', 'title': 'Recommendation', 'category': 'details'}, {'text': 'Medium', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® VTune™ Profiler Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01122', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2024-08-13T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2024-08-13T00:00:00+00:00', 'initial_release_date': '2024-08-13T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01122.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'acknowledgments': [{'names': ['Intel would like to thank ycdxsb for reporting this issue. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-29015', 'title': 'Uncontrolled search path in some Intel® VTune™ Profiler software before versions 2024.1 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-31153 | INTEL-SA-01124 | Intel® QuickAssist Technology Software Advisory | A potential security vulnerabilities in some Intel® QuickAssist Technology software may allow escalation of privilege, denial of service or information disclosure. Intel is releasing software updates to mitigate this potential vulnerability. | MEDIUM | 2025-02-11 03:00:00+03:00 | 2025-02-11 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01124.html | 5bbbe1449ff537cfffbae6c2d1598aa28a09877090cae2f04a754172da05dfeb | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerabilities in some Intel® QuickAssist Technology software may allow escalation of privilege, denial of service or information disclosure. Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating Intel® QuickAssist Technology to version 2.2.0 or later.\xa0\r\nhttps://www.intel.com/content/www/us/en/download/765502/intel-quickassist-technology-driver-for-windows-hw-version-2-0.html', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® QuickAssist Technology Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01124', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2025-02-11T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2025-02-11T00:00:00+00:00', 'initial_release_date': '2025-02-11T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01124.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Copyright © Intel Corporation All rights reserved.'}, 'acknowledgments': [{'names': ['Intel would like to thank Aobo Wang of Chaitin Security Research Lab (CVE-2024-31858,CVE-2023-32277,CVE-2024-31153), ycdxsb (CVE-2024-29223), for reporting these issues. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-31153', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'title': 'Improper input validation for some Intel® QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.1, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N', 'userInteraction': 'PASSIVE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'NONE', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'HIGH', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'NONE'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-29223', 'cwe': {'id': 'CWE-427', 'name': 'Uncontrolled Search Path Element'}, 'title': 'Uncontrolled search path for some Intel® QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.7, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'HIGH', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'userInteraction': 'ACTIVE', 'attackComplexity': 'HIGH', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'HIGH', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-32277', 'cwe': {'id': 'CWE-822', 'name': 'Untrusted Pointer Dereference'}, 'title': 'Untrusted Pointer Dereference in I/O subsystem for some Intel® QAT software before version 2.0.5 may allow authenticated user to potentially enable information disclosure via local operating system access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.1, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 4.3, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N', 'userInteraction': 'PASSIVE', 'attackComplexity': 'LOW', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'NONE', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'LOW', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-31858', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'title': 'Out-of-bounds write for some Intel® QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7.3, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'HIGH', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2024-29223 | INTEL-SA-01124 | Intel® QuickAssist Technology Software Advisory | A potential security vulnerabilities in some Intel® QuickAssist Technology software may allow escalation of privilege, denial of service or information disclosure. Intel is releasing software updates to mitigate this potential vulnerability. | MEDIUM | 2025-02-11 03:00:00+03:00 | 2025-02-11 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01124.html | 74e2c8df9cfda35725b0c0c0e93f08e1aafd01414ae8bb6657ae8e6feaf7cc55 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerabilities in some Intel® QuickAssist Technology software may allow escalation of privilege, denial of service or information disclosure. Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating Intel® QuickAssist Technology to version 2.2.0 or later.\xa0\r\nhttps://www.intel.com/content/www/us/en/download/765502/intel-quickassist-technology-driver-for-windows-hw-version-2-0.html', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® QuickAssist Technology Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01124', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2025-02-11T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2025-02-11T00:00:00+00:00', 'initial_release_date': '2025-02-11T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01124.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Copyright © Intel Corporation All rights reserved.'}, 'acknowledgments': [{'names': ['Intel would like to thank Aobo Wang of Chaitin Security Research Lab (CVE-2024-31858,CVE-2023-32277,CVE-2024-31153), ycdxsb (CVE-2024-29223), for reporting these issues. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-31153', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'title': 'Improper input validation for some Intel® QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.1, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N', 'userInteraction': 'PASSIVE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'NONE', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'HIGH', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'NONE'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-29223', 'cwe': {'id': 'CWE-427', 'name': 'Uncontrolled Search Path Element'}, 'title': 'Uncontrolled search path for some Intel® QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.7, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'HIGH', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'userInteraction': 'ACTIVE', 'attackComplexity': 'HIGH', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'HIGH', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-32277', 'cwe': {'id': 'CWE-822', 'name': 'Untrusted Pointer Dereference'}, 'title': 'Untrusted Pointer Dereference in I/O subsystem for some Intel® QAT software before version 2.0.5 may allow authenticated user to potentially enable information disclosure via local operating system access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.1, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 4.3, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N', 'userInteraction': 'PASSIVE', 'attackComplexity': 'LOW', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'NONE', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'LOW', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-31858', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'title': 'Out-of-bounds write for some Intel® QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7.3, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'HIGH', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |
CVE-2023-32277 | INTEL-SA-01124 | Intel® QuickAssist Technology Software Advisory | A potential security vulnerabilities in some Intel® QuickAssist Technology software may allow escalation of privilege, denial of service or information disclosure. Intel is releasing software updates to mitigate this potential vulnerability. | MEDIUM | 2025-02-11 03:00:00+03:00 | 2025-02-11 03:00:00+03:00 | https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-01124.html | 94bc0c3f0eb7381386b3d00d53e04fb8bb6e5aa0e7b27d7768095cee8c7d1426 | 2026-05-29 08:17:14.865208+03:00 | 2026-06-25 11:41:12.780439+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'A potential security vulnerabilities in some Intel® QuickAssist Technology software may allow escalation of privilege, denial of service or information disclosure. Intel is releasing software updates to mitigate this potential vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': "Intel provides these materials as-is, with no express or implied warranties.\\r\\nAll products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. \\r\\nIntel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request.\\r\\nIntel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. (https://www.intel.com/content/www/us/en/support/articles/000022396/processors.html)\\r\\nIntel technologies' features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com.(http://intel.com) \\r\\nSome results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. \\r\\nIntel and the Intel logo are trademarks of Intel Corporation or its subsidiaries in the United States and other countries. \\r\\n© Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.", 'title': 'Legal Notices and Disclaimers', 'category': 'legal_disclaimer'}, {'text': 'Intel recommends updating Intel® QuickAssist Technology to version 2.2.0 or later.\xa0\r\nhttps://www.intel.com/content/www/us/en/download/765502/intel-quickassist-technology-driver-for-windows-hw-version-2-0.html', 'title': 'Recommendation', 'category': 'details'}, {'text': 'High', 'title': 'Severity rating', 'category': 'details'}, {'text': 'Software', 'title': 'Advisory Category', 'category': 'details'}, {'text': 'Escalation of Privilege, Denial of Service, Information Disclosure', 'title': 'Impact of vulnerability', 'category': 'details'}, {'text': 'Contact Intel PSIRT at mailto:secure@intel.com with any questions, requests for technical details, or proposed coordination with other parties. Please encrypt any sensitive details using our PGP key, which can be found at https://www.intel.com/content/www/us/en/security-center/pgp-public-key.html.', 'title': 'Contact', 'category': 'details'}], 'title': 'Intel® QuickAssist Technology Software Advisory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'INTEL-SA-01124', 'status': 'final', 'version': '1.0.0', 'revision_history': [{'date': '2025-02-11T00:00:00+00:00', 'number': '1.0.0', 'summary': 'Initial release'}], 'current_release_date': '2025-02-11T00:00:00+00:00', 'initial_release_date': '2025-02-11T00:00:00+00:00'}, 'publisher': {'name': 'Intel Corporation', 'category': 'vendor', 'namespace': 'https://www.intel.com', 'contact_details': 'secure@intel.com', 'issuing_authority': 'Intel Corporation is responsible for vulnerability handling across all Intel offerings.'}, 'references': [{'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01124.html', 'summary': 'Security Center'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Copyright © Intel Corporation All rights reserved.'}, 'acknowledgments': [{'names': ['Intel would like to thank Aobo Wang of Chaitin Security Research Lab (CVE-2024-31858,CVE-2023-32277,CVE-2024-31153), ycdxsb (CVE-2024-29223), for reporting these issues. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.']}]}, '__comment__': 'This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content you must provide attribution to Intel Corporation and provide a link to the original.', 'vulnerabilities': [{'cve': 'CVE-2024-31153', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'title': 'Improper input validation for some Intel® QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable denial of service via local access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.1, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N', 'userInteraction': 'PASSIVE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'NONE', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'HIGH', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'NONE'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-29223', 'cwe': {'id': 'CWE-427', 'name': 'Uncontrolled Search Path Element'}, 'title': 'Uncontrolled search path for some Intel® QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.7, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'HIGH', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 5.4, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'userInteraction': 'ACTIVE', 'attackComplexity': 'HIGH', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'HIGH', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2023-32277', 'cwe': {'id': 'CWE-822', 'name': 'Untrusted Pointer Dereference'}, 'title': 'Untrusted Pointer Dereference in I/O subsystem for some Intel® QAT software before version 2.0.5 may allow authenticated user to potentially enable information disclosure via local operating system access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.1, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 4.3, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N', 'userInteraction': 'PASSIVE', 'attackComplexity': 'LOW', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'NONE', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'LOW', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}, {'cve': 'CVE-2024-31858', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'title': 'Out-of-bounds write for some Intel® QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'cvss_v4': {'version': '4.0', 'baseScore': 7.3, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'HIGH', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'HIGH'}, 'products': ['See reference.']}], 'product_status': {'known_affected': ['See reference.']}}]} |