Lucene search

K
cveIntelCVE-2023-31246
HistoryAug 11, 2023 - 3:15 a.m.

CVE-2023-31246

2023-08-1103:15:31
CWE-276
intel
web.nvd.nist.gov
17
cve
2023
31246
intel
sdp
software
default permissions
vulnerability
local access

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

9.0%

Incorrect default permissions in some Intelยฎ SDP Tool software before version 1.4 build 5 may allow an authenticated user to potentially enable escalation of privilege via local access.

Affected configurations

Nvd
Vulners
Node
intelserver_debug_and_provisioning_toolRange<1.4
OR
intelserver_debug_and_provisioning_toolMatch1.4build_2
OR
intelserver_debug_and_provisioning_toolMatch1.4build_3
OR
intelserver_debug_and_provisioning_toolMatch1.4build_4
VendorProductVersionCPE
intelserver_debug_and_provisioning_tool*cpe:2.3:a:intel:server_debug_and_provisioning_tool:*:*:*:*:*:*:*:*
intelserver_debug_and_provisioning_tool1.4cpe:2.3:a:intel:server_debug_and_provisioning_tool:1.4:build_2:*:*:*:*:*:*
intelserver_debug_and_provisioning_tool1.4cpe:2.3:a:intel:server_debug_and_provisioning_tool:1.4:build_3:*:*:*:*:*:*
intelserver_debug_and_provisioning_tool1.4cpe:2.3:a:intel:server_debug_and_provisioning_tool:1.4:build_4:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "Intel(R) SDP Tool software",
    "versions": [
      {
        "version": "before version 1.4 build 5",
        "status": "affected"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

9.0%

Related for CVE-2023-31246