Improper access control in Intel products - CVE-2023-27517

 

Improper access control in Intel products - CVE-2023-27517

Published: February 28, 2024


Vulnerability identifier: #VU86896
CSH Severity: Low
CVSS v4: 5.2 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-27517
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions. A local user can bypass implemented security restrictions and gain elevated privileges.


Affected software

Intel Optane Persistent Memory 100 Series
Intel Optane Persistent Memory 200 Series
Intel Optane Persistent Memory 300 Series

How to mitigate CVE-2023-27517

Install updates from vendor's website.

Intel Optane Persistent Memory 100 Series - update to 01.00.00.3547
Intel Optane Persistent Memory 200 Series - update to 02.00.00.3915
Intel Optane Persistent Memory 300 Series - update to 03.00.00.0483

External References

Related Security Bulletins