MEDIUM✓ PATCH🇵🇱 Wersja polska

CVE-2022-40210

CVSS 6.8v3.1pub. 2023-05-10upd. 2024-11-21

Exposure of data element to wrong session in the Intel DCM software before version 5.0.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L
  • Intel Data Center Manager

    APP
    Intel
    < 5.0.1
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2023-31273CRITICAL10.0PL ✓same product

Krytyczna podatność privilege escalation w Intel Data Center Manager

CVE-2018-3679CRITICAL9.6PL ✓same product

Privilege escalation w Intel Data Center Manager SDK — nieautoryzowane RCE

CVE-2022-44619HIGH8.2same product

Insecure storage of sensitive information in the Intel(R) DCM software before version 5.1 may allow an authent...

CVE-2022-33942HIGH8.8same product

Protection mechanism failure in the Intel(R) DCM software before version 5.0 may allow an unauthenticated user...

CVE-2022-21225HIGH8.0same product

Improper neutralization in the Intel(R) Data Center Manager software before version 4.1 may allow an authentic...