Path traversal in Intel products - CVE-2023-24592
Published: November 23, 2023
Vulnerability identifier: #VU83466
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2023-24592
CWE-ID: CWE-22
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vendor: Intel
Affected software:
Intel Advisor
Intel Inspector
Intel oneAPI Base Toolkit
Intel oneAPI HPC Toolkit
MPI Library
Intel Advisor
Intel Inspector
Intel oneAPI Base Toolkit
Intel oneAPI HPC Toolkit
MPI Library
Detailed vulnerability description
The vulnerability allows a local user to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences. A local user can send a specially crafted HTTP request and read arbitrary files on the system, leading to privilege escalation.
How to mitigate CVE-2023-24592
Install update from vendor's website.