Lucene search

K
cveIntelCVE-2022-27638
HistoryNov 11, 2022 - 4:15 p.m.

CVE-2022-27638

2022-11-1116:15:13
CWE-427
intel
web.nvd.nist.gov
29
4
cve-2022-27638
intel
advanced link analyzer pro
vulnerability
privilege escalation
nvd

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

12.6%

Uncontrolled search path element in the Intelยฎ Advanced Link Analyzer Pro before version 22.2 and Standard edition software before version 22.1.1 STD may allow an authenticated user to potentially enable escalation of privilege via local access.

Affected configurations

Nvd
Node
inteladvanced_link_analyzerRange<22.1.1standard
OR
inteladvanced_link_analyzerRange<22.2pro
VendorProductVersionCPE
inteladvanced_link_analyzer*cpe:2.3:a:intel:advanced_link_analyzer:*:*:*:*:standard:*:*:*
inteladvanced_link_analyzer*cpe:2.3:a:intel:advanced_link_analyzer:*:*:*:*:pro:*:*:*

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "Intel(R) Advanced Link Analyzer Pro and Standard edition",
    "versions": [
      {
        "version": "See references",
        "status": "affected"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

Social References

More

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

12.6%

Related for CVE-2022-27638