CVE-2023-39432

Improper access control element in some Intel(R) Ethernet tools and driver install software, before versions 28.2, may allow an authenticated user to potentially enable escalation of privilege via local access.
Configurations

Configuration 1 (hide)

cpe:2.3:a:intel:ethernet_adapter_complete_driver:*:*:*:*:*:*:*:*

History

24 Oct 2024, 19:13

Type Values Removed Values Added
First Time Intel
Intel ethernet Adapter Complete Driver
CWE NVD-CWE-noinfo
References () https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00993.html - () https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00993.html - Vendor Advisory
CPE cpe:2.3:a:intel:ethernet_adapter_complete_driver:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : 6.7
v2 : unknown
v3 : 7.8
Summary
  • (es) Un elemento de control de acceso inadecuado en algunas herramientas Intel(R) Ethernet y software de instalación de controladores, anteriores a las versiones 28.2, puede permitir que un usuario autenticado habilite potencialmente la escalada de privilegios a través del acceso local.

14 Feb 2024, 15:01

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-14 14:16

Updated : 2024-10-24 19:13


NVD link : CVE-2023-39432

Mitre link : CVE-2023-39432

CVE.ORG link : CVE-2023-39432


JSON object : View

Products Affected

intel

  • ethernet_adapter_complete_driver
CWE
NVD-CWE-noinfo CWE-284

Improper Access Control