Improper access control in Intel products - CVE-2022-2827

 

Improper access control in Intel products - CVE-2022-2827

Published: December 6, 2022


Vulnerability identifier: #VU69917
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-2827
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions. A remote attacker can bypass implemented security restrictions and gain unauthorized access to sensitive information on the system.


Affected software

Intel Server Board M10JNP2SB
Intel Server Board M70KLP2SB
Intel Server Board M20NTP
Cloudline CL4150 Gen10 Server
PowerProtect DD2200

How to mitigate CVE-2022-2827

Install updates from vendor's website.

Intel Server Board M10JNP2SB - update to 1.11
Intel Server Board M70KLP2SB - update to 4.15
Intel Server Board M20NTP - update to 0027
Cloudline CL4150 Gen10 Server - update to 3.09.0.0
PowerProtect DD2200 - update to 6.2.1.120

External References

Related Security Bulletins