Lucene search

K
cveIntelCVE-2023-24592
HistoryNov 14, 2023 - 7:15 p.m.

CVE-2023-24592

2023-11-1419:15:18
CWE-22
intel
web.nvd.nist.gov
23
cve-2023-24592
path traversal
intel
oneapi toolkits
component software
escalation of privilege
security vulnerability

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.7

Confidence

High

EPSS

0

Percentile

10.5%

Path traversal in the some Intelยฎ oneAPI Toolkits and Component software before version 2023.1 may allow authenticated user to potentially enable escalation of privilege via local access.

Affected configurations

Nvd
Node
inteladvisorRange<2023.1
OR
intelinspectorRange<2023.1
OR
intelmpi_libraryRange<2023.1
OR
inteloneapi_base_toolkitRange<2023.1
OR
inteloneapi_hpc_toolkitRange<2023.1
VendorProductVersionCPE
inteladvisor*cpe:2.3:a:intel:advisor:*:*:*:*:*:*:*:*
intelinspector*cpe:2.3:a:intel:inspector:*:*:*:*:*:*:*:*
intelmpi_library*cpe:2.3:a:intel:mpi_library:*:*:*:*:*:*:*:*
inteloneapi_base_toolkit*cpe:2.3:a:intel:oneapi_base_toolkit:*:*:*:*:*:*:*:*
inteloneapi_hpc_toolkit*cpe:2.3:a:intel:oneapi_hpc_toolkit:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "Intel(R) oneAPI Toolkits and Component software",
    "versions": [
      {
        "version": "before version 2023.1",
        "status": "affected"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.7

Confidence

High

EPSS

0

Percentile

10.5%

Related for CVE-2023-24592