2023-08-18 16:00:35 +00:00

264 lines
10 KiB
JSON

{
"id": "CVE-2023-28823",
"sourceIdentifier": "secure@intel.com",
"published": "2023-08-11T03:15:26.530",
"lastModified": "2023-08-18T15:03:45.797",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493 may allow an authenticated user to potentially enable escalation of privilege via local access."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
"attackVector": "LOCAL",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "REQUIRED",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 7.3,
"baseSeverity": "HIGH"
},
"exploitabilityScore": 1.3,
"impactScore": 5.9
},
{
"source": "secure@intel.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H",
"attackVector": "LOCAL",
"attackComplexity": "HIGH",
"privilegesRequired": "LOW",
"userInteraction": "REQUIRED",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 6.7,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 0.8,
"impactScore": 5.9
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-427"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:intel:advisor_for_oneapi:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2023.1",
"matchCriteriaId": "2193AD3C-C7CF-47BC-B9C7-043A44263881"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:intel:cpu_runtime_for_opencl_applications:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2023.1",
"matchCriteriaId": "268A0E9F-941F-4D2A-821D-4D1032458484"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:intel:distribution_for_python_programming_language:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2023.1",
"matchCriteriaId": "01C06498-09B0-434E-A9AB-F90225AEDF94"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:intel:dpc\\+\\+_compatibility_tool:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2023.1",
"matchCriteriaId": "5449D057-151E-49F1-A4F3-9B59BCABAAED"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:intel:embree_ray_tracing_kernel_library:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2023.1",
"matchCriteriaId": "EA34171F-6851-4C68-B9DD-E087DA9CD29D"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:intel:fortran_compiler:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2023.1",
"matchCriteriaId": "CB6F5C5E-9330-4957-899F-EA81A7829FCE"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:intel:implicit_spmd_program_compiler:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.19.1",
"matchCriteriaId": "309CC033-7419-45B0-B57E-EDB855D6ED8D"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:intel:inspector_for_oneapi:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2023.1",
"matchCriteriaId": "B2EFA075-DD70-416E-9591-827FAC2AD89F"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:intel:integrated_performance_primitives:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2021.8",
"matchCriteriaId": "BD85FB58-421A-4959-97BD-437D9445767B"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:intel:ipp_cryptography:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2021.7.0",
"matchCriteriaId": "A27AABCE-03AA-4A04-8950-A7B3AA41829C"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:intel:mpi_library:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2021.9.0",
"matchCriteriaId": "09DEC669-B8A6-4E41-B34C-F6D2F710D96F"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:intel:oneapi_base_toolkit:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2023.1",
"matchCriteriaId": "E9B0E003-2303-4BAA-AAB5-E41672DD36A8"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:intel:oneapi_data_analytics_library:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2023.1",
"matchCriteriaId": "CB4E3234-E4F4-4A1A-92C8-7A71741A2280"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:intel:oneapi_deep_neural_network_library:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2023.1",
"matchCriteriaId": "BB8E84AA-7C56-4F06-9CBD-0F8265EA164B"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:intel:oneapi_dpc\\+\\+\\/c\\+\\+_compiler:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2023.1",
"matchCriteriaId": "86839DB5-6A37-456F-8527-E1D6CFF9592D"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:intel:oneapi_dpc\\+\\+_library_\\(onedpl\\):*:*:*:*:*:*:*:*",
"versionEndExcluding": "2022.1",
"matchCriteriaId": "4F404777-A45E-4D04-A459-20440919DA6F"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:intel:oneapi_hpc_toolkit:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2023.1",
"matchCriteriaId": "140E6A32-DD35-4BD9-8810-26359D76FEB7"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:intel:oneapi_iot_toolkit:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2023.1",
"matchCriteriaId": "2F00829C-D33E-4BF6-A699-16C4E7A9E95B"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:intel:oneapi_math_kernel_library:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2023.1",
"matchCriteriaId": "0D429AB0-77B9-4F05-B59B-95DFC3DF9D4F"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:intel:oneapi_rendering_toolkit:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2023.1",
"matchCriteriaId": "7297C4CE-B6AB-4BBA-89DE-CA0865F8CCBB"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:intel:oneapi_threading_building_blocks:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2021.9.0",
"matchCriteriaId": "72297C84-0B91-4D8E-A87F-235E3DC346E1"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:intel:oneapi_toolkit_and_component_software_installer:*:*:*:*:*:*:*:*",
"versionEndExcluding": "4.3.1.493",
"matchCriteriaId": "7BFF1F97-F77D-496F-97F4-E2A706B6AB33"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:intel:oneapi_video_processing_library:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2023.1",
"matchCriteriaId": "E2CF5D27-1C7C-4FDF-B3A0-4EE4047195C6"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:intel:open_image_denoise:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.4.3",
"matchCriteriaId": "65B820BD-07FB-48AC-B3E4-F3DCAB991C9B"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:intel:open_volume_kernel_library:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2023.1",
"matchCriteriaId": "0158081D-D9FD-4918-ADCF-70AB92230B99"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:intel:ospray:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2023.1",
"matchCriteriaId": "D02EF185-A6E6-4820-A084-60AD061283A7"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:intel:ospray_studio:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2023.1",
"matchCriteriaId": "FB7158BB-56CF-40BA-85CF-0B622CC49617"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:intel:trace_analyzer_and_collector:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2021.9.0",
"matchCriteriaId": "F034E3C1-6FA9-4F75-80AE-98857F323AA2"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:intel:vtune_profiler_for_oneapi:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2023.1",
"matchCriteriaId": "21CFEA3C-4017-44FB-9A25-193FE8D65375"
}
]
}
]
}
],
"references": [
{
"url": "http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00890.html",
"source": "secure@intel.com",
"tags": [
"Vendor Advisory"
]
}
]
}