Path traversal in Intel products - CVE-2023-24592

 

Path traversal in Intel products - CVE-2023-24592

Published: November 23, 2023


Vulnerability identifier: #VU83466
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-24592
CWE-ID: CWE-22
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences. A local user can send a specially crafted HTTP request and read arbitrary files on the system, leading to privilege escalation.


Affected software

MPI Library
Intel Advisor
Intel Inspector
Intel oneAPI Base Toolkit
Intel oneAPI HPC Toolkit

How to mitigate CVE-2023-24592

Install update from vendor's website.

MPI Library - update to 2021.9
Intel Advisor - update to 2023.1
Intel Inspector - update to 2023.1
Intel oneAPI Base Toolkit - update to 2023.1
Intel oneAPI HPC Toolkit - update to 2023.1

External References

Related Security Bulletins