MEDIUM✓ PATCH🇬🇧 English

CVE-2022-40210

CVSS 6.8v3.1pub. 2023-05-10upd. 2024-11-21

Exposure of data element to wrong session in the Intel DCM software before version 5.0.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

oryginał EN
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L
  • Intel Data Center Manager

    APP
    Intel
    < 5.0.1
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
CWE
Referencje

Powiązane podatności

CVE-2023-31273CRITICAL10.0PL ✓ten sam produkt

Krytyczna podatność privilege escalation w Intel Data Center Manager

CVE-2018-3679CRITICAL9.6PL ✓ten sam produkt

Privilege escalation w Intel Data Center Manager SDK — nieautoryzowane RCE

CVE-2022-44619HIGH8.2ten sam produkt

Insecure storage of sensitive information in the Intel(R) DCM software before version 5.1 may allow an authent...

CVE-2022-33942HIGH8.8ten sam produkt

Protection mechanism failure in the Intel(R) DCM software before version 5.0 may allow an unauthenticated user...

CVE-2022-21225HIGH8.0ten sam produkt

Improper neutralization in the Intel(R) Data Center Manager software before version 4.1 may allow an authentic...