Loading HuntDB...

Vulnerabilities

CVE-2023-35121

HIGH

Improper access control in the Intel(R) oneAPI DPC++/C++ Compiler before version 2022.2.1 for some Intel(R) oneAPI Toolkits before version 2022.3.1 may allow authenticated user to potentially enable escalation of privilege via local access.

Published Feb 14, 2024

CVE-2023-35060

MEDIUM

Uncontrolled search path in some Intel(R) Battery Life Diagnostic Tool software before version 2.3.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

Published Feb 14, 2024

CVE-2023-35062

MEDIUM

Improper access control in some Intel(R) DSA software before version 23.4.33 may allow a privileged user to potentially enable escalation of privilege via local access.

Published Feb 14, 2024

CVE-2023-39425

HIGH

Improper access control in some Intel(R) DSA software before version 23.4.33 may allow an authenticated user to potentially enable escalation of privilege via local access.

Published Feb 14, 2024

CVE-2023-35769

MEDIUM

Uncontrolled search path in some Intel(R) CIP software before version 2.4.10577 may allow an authenticated user to potentially enable escalation of privilege via local access.

Published Feb 14, 2024

CVE-2023-38135

MEDIUM

Improper authorization in some Intel(R) PM software may allow a privileged user to potentially enable escalation of privilege via local access.

Published Feb 14, 2024

CVE-2023-32618

MEDIUM

Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

Published Feb 14, 2024

CVE-2023-28407

MEDIUM

Uncontrolled search path in some Intel(R) XTU software before version 7.12.0.29 may allow an authenticated user to potentially enable escalation of privilege via local access.

Published Feb 14, 2024

CVE-2023-32647

MEDIUM

Improper access control in some Intel(R) XTU software before version 7.12.0.29 may allow an authenticated user to potentially enable escalation of privilege via local access.

Published Feb 14, 2024

CVE-2023-34351

HIGH

Buffer underflow in some Intel(R) PCM software before version 202307 may allow an unauthenticated user to potentially enable denial of service via network access.

Published Feb 14, 2024

CVE-2023-35003

MEDIUM

Path transversal in some Intel(R) VROC software before version 8.0.8.1001 may allow an authenticated user to potentially enable escalation of privilege via local access.

Published Feb 14, 2024

CVE-2023-34315

MEDIUM

Incorrect default permissions in some Intel(R) VROC software before version 8.0.8.1001 may allow an authenticated user to potentially enable escalation of privilege via local access.

Published Feb 14, 2024

CVE-2023-32646

MEDIUM

Uncontrolled search path element in some Intel(R) VROC software before version 8.0.8.1001 may allow an authenticated user to potentially enable escalation of privilege via local access.

Published Feb 14, 2024

CVE-2023-31271

MEDIUM

Improper access control in some Intel(R) VROC software before version 8.0.8.1001 may allow an authenticated user to potentially enable escalation of privilege via local access.

Published Feb 14, 2024

CVE-2023-27517

MEDIUM

Improper access control in some Intel(R) Optane(TM) PMem software before versions 01.00.00.3547, 02.00.00.3915, 03.00.00.0483 may allow an athenticated user to potentially enable escalation of privilege via local access.

Published Feb 14, 2024

CVE-2023-25951

MEDIUM

Improper input validation for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow a privileged user to potentially enable escalation of privilege via local access.

Published Feb 14, 2024

CVE-2023-28739

MEDIUM

Incorrect default permissions in some Intel(R) Chipset Driver Software before version 10.1.19444.8378 may allow an authenticated user to potentially enable escalation of privilege via local access.

Published Feb 14, 2024

CVE-2023-32280

MEDIUM

Insufficiently protected credentials in some Intel(R) Server Product OpenBMC firmware before versions egs-1.05 may allow an unauthenticated user to enable information disclosure via network access.

Published Feb 14, 2024

CVE-2023-41231

MEDIUM

Incorrect default permissions in some ACAT software maintained by Intel(R) before version 2.0.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

Published Feb 14, 2024

CVE-2023-25779

MEDIUM

Uncontrolled search path element in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable escalation of privilege via local access.

Published Feb 14, 2024

CVE-2023-28740

MEDIUM

Uncontrolled search path element in some Intel(R) QAT drivers for Windows - HW Version 2.0 before version 2.0.4 may allow an authenticated user to potentially enable escalation of privilege via local access.

Published Nov 14, 2023

CVE-2022-33945

HIGH

Improper input validation in some Intel(R) Server board and Intel(R) Server System BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.

Published Nov 14, 2023

CVE-2023-32204

HIGH

Improper access control in some Intel(R) OFU software before version 14.1.31 may allow an authenticated user to potentially enable escalation of privilege via local access.

Published Nov 14, 2023

CVE-2023-22327

MEDIUM

Out-of-bounds write in firmware for some Intel(R) FPGA products before version 2.8.1 may allow a privileged user to potentially enable information disclosure via local access.

Published Nov 14, 2023

CVE-2023-22305

MEDIUM

Integer overflow in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enable denial of service via local access.

Published Nov 14, 2023

CVE-2022-41700

MEDIUM

Insecure inherited permissions in some Intel(R) NUC Pro Software Suite installation software before version 2.0.0.9 may allow an authenticated user to potentially enable escalation of privilege via local access.

Published Nov 14, 2023

CVE-2022-27229

MEDIUM

Path transversal in some Intel(R) NUC Kits NUC7i3DN, NUC7i5DN, NUC7i7DN HDMI firmware update tool software before version 1.79.1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

Published Nov 14, 2023

CVE-2023-28397

HIGH

Improper access control in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated to potentially enable escalation of privileges via local access.

Published Nov 14, 2023

CVE-2023-28737

HIGH

Improper initialization in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enable escalation of privilege via local access.

Published Nov 14, 2023

CVE-2023-4324

UNKNOWN

Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP Content-Security-Policy headers

Published Aug 15, 2023

CVE-2023-4325

UNKNOWN

Broadcom RAID Controller web interface is vulnerable due to usage of Libcurl with LSA has known vulnerabilities

Published Aug 15, 2023

CVE-2023-4326

UNKNOWN

Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration that supports obsolete SHA1-based ciphersuites

Published Aug 15, 2023

CVE-2023-4329

UNKNOWN

Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safeguard SESSIONID cookie with SameSite attribute

Published Aug 15, 2023

CVE-2023-4331

UNKNOWN

Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration that support obsolete and vulnerable TLS protocols

Published Aug 15, 2023

CVE-2023-4332

UNKNOWN

Broadcom RAID Controller web interface is vulnerable due to Improper permissions on the log file

Published Aug 15, 2023

CVE-2023-4334

UNKNOWN

Broadcom RAID Controller Web server (nginx) is serving private files without any authentication

Published Aug 15, 2023

CVE-2023-4335

UNKNOWN

Broadcom RAID Controller Web server (nginx) is serving private server-side files without any authentication on Linux

Published Aug 15, 2023

CVE-2023-4336

UNKNOWN

Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safeguard cookies with Secure attribute

Published Aug 15, 2023

CVE-2023-4337

UNKNOWN

Broadcom RAID Controller web interface is vulnerable to improper session handling of managed servers on Gateway installation

Published Aug 15, 2023

CVE-2023-4338

UNKNOWN

Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not provide X-Content-Type-Options Headers

Published Aug 15, 2023

CVE-2023-4339

UNKNOWN

Broadcom RAID Controller web interface is vulnerable to exposure of private keys used for CIM stored with insecure file permissions

Published Aug 15, 2023

CVE-2023-4340

UNKNOWN

Broadcom RAID Controller is vulnerable to Privilege escalation by taking advantage of the Session prints in the log file

Published Aug 15, 2023

CVE-2023-4341

UNKNOWN

Broadcom RAID Controller is vulnerable to Privilege escalation to root due to creation of insecure folders by Web GUI

Published Aug 15, 2023

CVE-2023-4342

UNKNOWN

Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP strict-transport-security policy

Published Aug 15, 2023

CVE-2023-4343

UNKNOWN

Broadcom RAID Controller web interface is vulnerable due to exposure of sensitive password information in the URL as a URL search parameter

Published Aug 15, 2023

CVE-2023-4344

UNKNOWN

Broadcom RAID Controller web interface is vulnerable to insufficient randomness due to improper use of ssl.rnd to setup CIM connection

Published Aug 15, 2023

CVE-2023-4323

UNKNOWN

Broadcom RAID Controller web interface is vulnerable to improper session management of active sessions on Gateway setup

Published Aug 15, 2023

CVE-2023-4345

UNKNOWN

Broadcom RAID Controller web interface is vulnerable client-side control bypass leads to unauthorized data access for low privileged user

Published Aug 15, 2023

CVE-2022-36372

HIGH

Improper buffer restrictions in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.

Published Aug 11, 2023

CVE-2023-22449

HIGH

Improper input validation in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.

Published Aug 11, 2023