7.8
CVE-2023-22355
- EPSS 0.08%
- Published 10.05.2023 14:15:27
- Last modified 21.11.2024 07:44:37
- Source secure@intel.com
- Teams watchlist Login
- Open Login
Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.0.251 may allow an authenticated user to potentially enable escalation of privilege via local access.
Data is provided by the National Vulnerability Database (NVD)
Intel ≫ Cpu Runtime SwPlatformopencl Version < 2023.0
Intel ≫ Distribution For Python Version < 2023.0
Intel ≫ Dpc++ Compatibility Tool Version < 2023.0
Intel ≫ Embree Ray Tracing Kernel Library Version < 2023.0
Intel ≫ Fortran Compiler Version < 2023.0
Intel ≫ Implicit Spmd Program Compiler Version < 1.18.1
Intel ≫ Integrated Performance Primitives Version < 2021.7
Intel ≫ Integrated Performance Primitives Cryptography Version < 2021.6.3
Intel ≫ Mpi Library Version < 2021.8
Intel ≫ Oneapi Base Toolkit Version < 2023.0
Intel ≫ Oneapi Data Analytics Library Version < 2023.0
Intel ≫ Oneapi Deep Neural Network Library Version < 2023.0
Intel ≫ Oneapi Dpc++/c++ Compiler Version < 2023.0
Intel ≫ Oneapi Dpc++ Library Version < 2022.0
Intel ≫ Oneapi Hpc Toolkit Version < 2023.0.0
Intel ≫ Oneapi Hpc Toolkit Version2023.0.0
Intel ≫ Oneapi Iot Toolkit Version < 2023.0
Intel ≫ Oneapi Math Kernel Library Version < 2023.0
Intel ≫ Oneapi Rendering Toolkit Version < 2023.0
Intel ≫ Oneapi Threading Building Blocks Version < 2021.8
Intel ≫ Oneapi Toolkit And Component Software Installers Version < 4.3.0.251
Intel ≫ Oneapi Video Processing Library Version < 2023.0
Intel ≫ Open Image Denoise Version < 1.4.3
Intel ≫ Open Volume Kernel Library Version < 2023.0
Intel ≫ Ospray Studio Version < 2023.0
Intel ≫ Trace Analyzer And Collector Version < 2021.8.0
Intel ≫ Vtune Profiler Version < 2023.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.08% | 0.214 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
secure@intel.com | 6.7 | 0.8 | 5.9 |
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
|
CWE-427 Uncontrolled Search Path Element
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.