Lucene search

K
cveIntelCVE-2023-34355
HistoryAug 11, 2023 - 3:15 a.m.

CVE-2023-34355

2023-08-1103:15:34
CWE-427
intel
web.nvd.nist.gov
11
cve-2023-34355
vulnerability
intel
server board
m10jnp2sb
bmc
video drivers
privilege escalation
nvd
windows
linux

CVSS3

7.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

EPSS

0

Percentile

9.0%

Uncontrolled search path element for some Intelยฎ Server Board M10JNP2SB integrated BMC video drivers before version 3.0 for Microsoft Windows and before version 1.13.4 for linux may allow an authenticated user to potentially enable escalation of privilege via local access.

Affected configurations

Nvd
Node
intelintegrated_bmc_video_driverRange<1.13.4linux
OR
intelintegrated_bmc_video_driverRange<3.0windows
AND
intelserver_board_m10jnp2sbMatch-
VendorProductVersionCPE
intelintegrated_bmc_video_driver*cpe:2.3:a:intel:integrated_bmc_video_driver:*:*:*:*:*:linux:*:*
intelintegrated_bmc_video_driver*cpe:2.3:a:intel:integrated_bmc_video_driver:*:*:*:*:*:windows:*:*
intelserver_board_m10jnp2sb-cpe:2.3:h:intel:server_board_m10jnp2sb:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "Intel(R) Server Board M10JNP2SB integrated BMC video drivers",
    "versions": [
      {
        "version": "before version 3.0 for Microsoft Windows and before version 1.13.4 for linux",
        "status": "affected"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

CVSS3

7.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

EPSS

0

Percentile

9.0%

Related for CVE-2023-34355