6.7

CVE-2023-27391

Improper access control in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493 may allow a privileged user to potentially enable escalation of privilege via local access.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IntelAdvisor For Oneapi Version < 2023.1
IntelDpc++ Compatibility Tool Version < 2023.1
IntelFortran Compiler Version < 2023.1
IntelInspector For Oneapi Version < 2023.1
IntelIpp Cryptography Version < 2021.7.0
IntelMpi Library Version < 2021.9.0
IntelOneapi Base Toolkit Version < 2023.1
IntelOneapi Data Analytics Library Version < 2023.1
IntelOneapi Dpc++/c++ Compiler Version < 2023.1
IntelOneapi Dpc++ Library (onedpl) Version < 2022.1
IntelOneapi Hpc Toolkit Version < 2023.1
IntelOneapi Iot Toolkit Version < 2023.1
IntelOneapi Math Kernel Library Version < 2023.1
IntelOneapi Rendering Toolkit Version < 2023.1
IntelOneapi Threading Building Blocks Version < 2021.9.0
IntelOpen Image Denoise Version < 1.4.3
IntelOpen Volume Kernel Library Version < 2023.1
IntelOspray Version < 2023.1
IntelOspray Studio Version < 2023.1
IntelTrace Analyzer And Collector Version < 2021.9.0
IntelVtune Profiler For Oneapi Version < 2023.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.04% 0.11
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
secure@intel.com 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.