Improper handling of exceptional conditions in Intel products - CVE-2023-43753

 

Improper handling of exceptional conditions in Intel products - CVE-2023-43753

Published: September 17, 2024


Vulnerability identifier: #VU97443
CSH Severity: Low
CVSS v4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-43753
CWE-ID: CWE-755
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to improper handling of errors in Intel Processors with Intel Software Guard Extensions. A local user can gain access to sensitive information.


Affected software

Intel Xeon D Processors
3rd Generation Intel Xeon Scalable Processors
Intel Xeon E Processors
Precision 7920 Rack
Precision 7920 XL Rack
HPE SimpliVity 380 Gen10
HPE SimpliVity 380 Gen10 G
HPE SimpliVity 380 Gen10 H
HPE SimpliVity 190r Gen10 Server
HPE SimpliVity 170r Gen10 Server
HPE SimpliVity 380 Gen10 Plus
HPE SimpliVity 380 Gen11
F5OS
APEX Cloud Platform for Microsoft Azure

How to mitigate CVE-2023-43753

Install updates from vendor's website.

APEX Cloud Platform for Microsoft Azure - update to 01.03.00.00
Precision 7920 Rack - update to 2.22.2
Precision 7920 XL Rack - update to 2.22.2
HPE SimpliVity 380 Gen10 - update to 2024_1129
HPE SimpliVity 380 Gen10 G - update to 2024_1129
HPE SimpliVity 380 Gen10 H - update to 2024_1129
HPE SimpliVity 190r Gen10 Server - update to 2024_1129
HPE SimpliVity 170r Gen10 Server - update to 2024_1129
HPE SimpliVity 380 Gen10 Plus - update to 2024_1129
HPE SimpliVity 380 Gen11 - update to 2024_1129

External References

Related Security Bulletins