Lucene search

K
cveIntelCVE-2018-12175
HistorySep 12, 2018 - 7:29 p.m.

CVE-2018-12175

2018-09-1219:29:02
CWE-276
intel
web.nvd.nist.gov
52
cve-2018-12175
intel distribution for python
idp
directory permissions
privileges
local access

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.5

Confidence

High

EPSS

0

Percentile

12.6%

Default install directory permissions in Intel Distribution for Python (IDP) version 2018 may allow an unprivileged user to escalate privileges via local access.

Affected configurations

Nvd
Node
inteldistribution_for_pythonMatch2018
VendorProductVersionCPE
inteldistribution_for_python2018cpe:2.3:a:intel:distribution_for_python:2018:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Intel(R) Distribution for Python 2018",
    "vendor": "Intel Corporation",
    "versions": [
      {
        "status": "affected",
        "version": "Intel(R) Distribution for Python 2018 downloaded before Aug 6, 2018."
      }
    ]
  }
]

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.5

Confidence

High

EPSS

0

Percentile

12.6%

Related for CVE-2018-12175