Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-28938
HistoryAug 11, 2023 - 12:00 a.m.

CVE-2023-28938

2023-08-1100:00:00
ubuntu.com
ubuntu.com
10
cve-2023-28938
uncontrolled resource consumption
intel ssd tools
denial of service
local access
mdadm-4.2-rc2

4.4 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

0.0004 Low

EPSS

Percentile

9.2%

Uncontrolled resource consumption in some Intelยฎ SSD Tools software
before version mdadm-4.2-rc2 may allow a priviledged user to potentially
enable denial of service via local access.

Notes

Author Note
Priority reason: Denial of service in command line tool option only
mdeslaur mdadm generally requires root privileges

4.4 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

0.0004 Low

EPSS

Percentile

9.2%