Lucene search

K
cveIntelCVE-2023-38420
HistoryMay 16, 2024 - 9:15 p.m.

CVE-2023-38420

2024-05-1621:15:52
CWE-754
CWE-703
intel
web.nvd.nist.gov
27
intel power gadget
macos
info disclosure
improper conditions check
nvd

CVSS3

3.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

AI Score

6

Confidence

Low

EPSS

0

Percentile

9.0%

Improper conditions check in Intel® Power Gadget software for macOS all versions may allow an authenticated user to potentially enable information disclosure via local access.

Affected configurations

Vulnrichment
Node
intelpower_gadget_software
VendorProductVersionCPE
intelpower_gadget_software*cpe:2.3:a:intel:power_gadget_software:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "Intel(R) Power Gadget software for macOS",
    "versions": [
      {
        "version": "See references",
        "status": "affected"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

CVSS3

3.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

AI Score

6

Confidence

Low

EPSS

0

Percentile

9.0%

Related for CVE-2023-38420