2023-08-11 04:00:32 +00:00
{
"id" : "CVE-2023-28823" ,
"sourceIdentifier" : "secure@intel.com" ,
"published" : "2023-08-11T03:15:26.530" ,
2023-08-18 16:00:35 +00:00
"lastModified" : "2023-08-18T15:03:45.797" ,
"vulnStatus" : "Analyzed" ,
2023-08-11 04:00:32 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493 may allow an authenticated user to potentially enable escalation of privilege via local access."
}
] ,
"metrics" : {
"cvssMetricV31" : [
2023-08-18 16:00:35 +00:00
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" ,
"attackVector" : "LOCAL" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "REQUIRED" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
"availabilityImpact" : "HIGH" ,
"baseScore" : 7.3 ,
"baseSeverity" : "HIGH"
} ,
"exploitabilityScore" : 1.3 ,
"impactScore" : 5.9
} ,
2023-08-11 04:00:32 +00:00
{
"source" : "secure@intel.com" ,
"type" : "Secondary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" ,
"attackVector" : "LOCAL" ,
"attackComplexity" : "HIGH" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "REQUIRED" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
"availabilityImpact" : "HIGH" ,
"baseScore" : 6.7 ,
"baseSeverity" : "MEDIUM"
} ,
"exploitabilityScore" : 0.8 ,
"impactScore" : 5.9
}
]
} ,
2023-08-18 16:00:35 +00:00
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-427"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:intel:advisor_for_oneapi:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "2023.1" ,
"matchCriteriaId" : "2193AD3C-C7CF-47BC-B9C7-043A44263881"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:intel:cpu_runtime_for_opencl_applications:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "2023.1" ,
"matchCriteriaId" : "268A0E9F-941F-4D2A-821D-4D1032458484"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:intel:distribution_for_python_programming_language:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "2023.1" ,
"matchCriteriaId" : "01C06498-09B0-434E-A9AB-F90225AEDF94"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:intel:dpc\\+\\+_compatibility_tool:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "2023.1" ,
"matchCriteriaId" : "5449D057-151E-49F1-A4F3-9B59BCABAAED"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:intel:embree_ray_tracing_kernel_library:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "2023.1" ,
"matchCriteriaId" : "EA34171F-6851-4C68-B9DD-E087DA9CD29D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:intel:fortran_compiler:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "2023.1" ,
"matchCriteriaId" : "CB6F5C5E-9330-4957-899F-EA81A7829FCE"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:intel:implicit_spmd_program_compiler:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "1.19.1" ,
"matchCriteriaId" : "309CC033-7419-45B0-B57E-EDB855D6ED8D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:intel:inspector_for_oneapi:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "2023.1" ,
"matchCriteriaId" : "B2EFA075-DD70-416E-9591-827FAC2AD89F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:intel:integrated_performance_primitives:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "2021.8" ,
"matchCriteriaId" : "BD85FB58-421A-4959-97BD-437D9445767B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:intel:ipp_cryptography:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "2021.7.0" ,
"matchCriteriaId" : "A27AABCE-03AA-4A04-8950-A7B3AA41829C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:intel:mpi_library:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "2021.9.0" ,
"matchCriteriaId" : "09DEC669-B8A6-4E41-B34C-F6D2F710D96F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:intel:oneapi_base_toolkit:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "2023.1" ,
"matchCriteriaId" : "E9B0E003-2303-4BAA-AAB5-E41672DD36A8"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:intel:oneapi_data_analytics_library:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "2023.1" ,
"matchCriteriaId" : "CB4E3234-E4F4-4A1A-92C8-7A71741A2280"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:intel:oneapi_deep_neural_network_library:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "2023.1" ,
"matchCriteriaId" : "BB8E84AA-7C56-4F06-9CBD-0F8265EA164B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:intel:oneapi_dpc\\+\\+\\/c\\+\\+_compiler:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "2023.1" ,
"matchCriteriaId" : "86839DB5-6A37-456F-8527-E1D6CFF9592D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:intel:oneapi_dpc\\+\\+_library_\\(onedpl\\):*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "2022.1" ,
"matchCriteriaId" : "4F404777-A45E-4D04-A459-20440919DA6F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:intel:oneapi_hpc_toolkit:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "2023.1" ,
"matchCriteriaId" : "140E6A32-DD35-4BD9-8810-26359D76FEB7"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:intel:oneapi_iot_toolkit:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "2023.1" ,
"matchCriteriaId" : "2F00829C-D33E-4BF6-A699-16C4E7A9E95B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:intel:oneapi_math_kernel_library:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "2023.1" ,
"matchCriteriaId" : "0D429AB0-77B9-4F05-B59B-95DFC3DF9D4F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:intel:oneapi_rendering_toolkit:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "2023.1" ,
"matchCriteriaId" : "7297C4CE-B6AB-4BBA-89DE-CA0865F8CCBB"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:intel:oneapi_threading_building_blocks:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "2021.9.0" ,
"matchCriteriaId" : "72297C84-0B91-4D8E-A87F-235E3DC346E1"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:intel:oneapi_toolkit_and_component_software_installer:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "4.3.1.493" ,
"matchCriteriaId" : "7BFF1F97-F77D-496F-97F4-E2A706B6AB33"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:intel:oneapi_video_processing_library:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "2023.1" ,
"matchCriteriaId" : "E2CF5D27-1C7C-4FDF-B3A0-4EE4047195C6"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:intel:open_image_denoise:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "1.4.3" ,
"matchCriteriaId" : "65B820BD-07FB-48AC-B3E4-F3DCAB991C9B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:intel:open_volume_kernel_library:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "2023.1" ,
"matchCriteriaId" : "0158081D-D9FD-4918-ADCF-70AB92230B99"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:intel:ospray:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "2023.1" ,
"matchCriteriaId" : "D02EF185-A6E6-4820-A084-60AD061283A7"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:intel:ospray_studio:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "2023.1" ,
"matchCriteriaId" : "FB7158BB-56CF-40BA-85CF-0B622CC49617"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:intel:trace_analyzer_and_collector:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "2021.9.0" ,
"matchCriteriaId" : "F034E3C1-6FA9-4F75-80AE-98857F323AA2"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:intel:vtune_profiler_for_oneapi:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "2023.1" ,
"matchCriteriaId" : "21CFEA3C-4017-44FB-9A25-193FE8D65375"
}
]
}
]
}
] ,
2023-08-11 04:00:32 +00:00
"references" : [
{
"url" : "http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00890.html" ,
2023-08-18 16:00:35 +00:00
"source" : "secure@intel.com" ,
"tags" : [
"Vendor Advisory"
]
2023-08-11 04:00:32 +00:00
}
]
}