Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4c2g-m3v7-xp4r

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.7

Описание

Insufficient input validation in HECI subsystem in Intel(R) CSME before version 11.21.55, Intel? Server Platform Services before version 4.0 and Intel? Trusted Execution Engine Firmware before version 3.1.55 may allow a privileged user to potentially enable escalation of privileges via local access.

Insufficient input validation in HECI subsystem in Intel(R) CSME before version 11.21.55, Intel? Server Platform Services before version 4.0 and Intel? Trusted Execution Engine Firmware before version 3.1.55 may allow a privileged user to potentially enable escalation of privileges via local access.

EPSS

Процентиль: 14%
0.00045
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 6.7
nvd
больше 6 лет назад

Insufficient input validation in HECI subsystem in Intel(R) CSME before version 11.21.55, Intel® Server Platform Services before version 4.0 and Intel® Trusted Execution Engine Firmware before version 3.1.55 may allow a privileged user to potentially enable escalation of privileges via local access.

EPSS

Процентиль: 14%
0.00045
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-20