Untrusted search path in Intel Server Platform Services Firmware - CVE-2023-29153

 

Untrusted search path in Intel Server Platform Services Firmware - CVE-2023-29153

Published: March 1, 2024


Vulnerability identifier: #VU86957
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-29153
CWE-ID: CWE-426
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to perform a denial of service (DoS) attack.

The vulnerability exists due to usage of an untrusted search path. A remote administrator can cause a denial of service condition on the target system.


Affected software

Intel Server Platform Services Firmware
Data Lakehouse
APEX Cloud Platform for Red Hat OpenShift
APEX Cloud Platform Foundation Software

How to mitigate CVE-2023-29153

Install updates from vendor's website.

Intel Server Platform Services Firmware - update to SPS_E5_06.01.04.002.0
Data Lakehouse - addressed in versions 2.1.5, 22.5.7
APEX Cloud Platform Foundation Software - update to 03.00.04.01
APEX Cloud Platform for Red Hat OpenShift - update to 4.13.39

External References

Related Security Bulletins