Описание
Uncontrolled search path in some Intel(R) FPGA SDK for OpenCL(TM) software technology may allow an authenticated user to potentially enable escalation of privilege via local access.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:intel:field_programmable_gate_array_software_development_kit_for_opencl:13.0:-:*:*:pro:*:*:*
cpe:2.3:a:intel:field_programmable_gate_array_software_development_kit_for_opencl:13.0:-:*:*:standard:*:*:*
cpe:2.3:a:intel:field_programmable_gate_array_software_development_kit_for_opencl:13.0:sp1:*:*:pro:*:*:*
cpe:2.3:a:intel:field_programmable_gate_array_software_development_kit_for_opencl:13.0:sp1:*:*:standard:*:*:*
cpe:2.3:a:intel:field_programmable_gate_array_software_development_kit_for_opencl:13.1:*:*:*:pro:*:*:*
cpe:2.3:a:intel:field_programmable_gate_array_software_development_kit_for_opencl:13.1:*:*:*:standard:*:*:*
cpe:2.3:a:intel:field_programmable_gate_array_software_development_kit_for_opencl:14.0:*:*:*:pro:*:*:*
cpe:2.3:a:intel:field_programmable_gate_array_software_development_kit_for_opencl:14.0:*:*:*:standard:*:*:*
cpe:2.3:a:intel:field_programmable_gate_array_software_development_kit_for_opencl:14.1:*:*:*:pro:*:*:*
cpe:2.3:a:intel:field_programmable_gate_array_software_development_kit_for_opencl:14.1:*:*:*:standard:*:*:*
cpe:2.3:a:intel:field_programmable_gate_array_software_development_kit_for_opencl:15.0:*:*:*:pro:*:*:*
cpe:2.3:a:intel:field_programmable_gate_array_software_development_kit_for_opencl:15.0:*:*:*:standard:*:*:*
cpe:2.3:a:intel:field_programmable_gate_array_software_development_kit_for_opencl:15.1:*:*:*:pro:*:*:*
cpe:2.3:a:intel:field_programmable_gate_array_software_development_kit_for_opencl:15.1:*:*:*:standard:*:*:*
cpe:2.3:a:intel:field_programmable_gate_array_software_development_kit_for_opencl:16.0:*:*:*:pro:*:*:*
cpe:2.3:a:intel:field_programmable_gate_array_software_development_kit_for_opencl:16.0:*:*:*:standard:*:*:*
cpe:2.3:a:intel:field_programmable_gate_array_software_development_kit_for_opencl:16.1:*:*:*:pro:*:*:*
cpe:2.3:a:intel:field_programmable_gate_array_software_development_kit_for_opencl:16.1:*:*:*:standard:*:*:*
cpe:2.3:a:intel:field_programmable_gate_array_software_development_kit_for_opencl:17.0:*:*:*:pro:*:*:*
cpe:2.3:a:intel:field_programmable_gate_array_software_development_kit_for_opencl:17.0:*:*:*:standard:*:*:*
cpe:2.3:a:intel:field_programmable_gate_array_software_development_kit_for_opencl:17.1:*:*:*:pro:*:*:*
cpe:2.3:a:intel:field_programmable_gate_array_software_development_kit_for_opencl:17.1:*:*:*:standard:*:*:*
cpe:2.3:a:intel:field_programmable_gate_array_software_development_kit_for_opencl:18.0:*:*:*:pro:*:*:*
cpe:2.3:a:intel:field_programmable_gate_array_software_development_kit_for_opencl:18.0:*:*:*:standard:*:*:*
cpe:2.3:a:intel:field_programmable_gate_array_software_development_kit_for_opencl:18.1:*:*:*:pro:*:*:*
cpe:2.3:a:intel:field_programmable_gate_array_software_development_kit_for_opencl:18.1:*:*:*:standard:*:*:*
cpe:2.3:a:intel:field_programmable_gate_array_software_development_kit_for_opencl:19.1:*:*:*:pro:*:*:*
cpe:2.3:a:intel:field_programmable_gate_array_software_development_kit_for_opencl:19.1:*:*:*:standard:*:*:*
cpe:2.3:a:intel:field_programmable_gate_array_software_development_kit_for_opencl:19.2:*:*:*:pro:*:*:*
cpe:2.3:a:intel:field_programmable_gate_array_software_development_kit_for_opencl:19.3:*:*:*:pro:*:*:*
cpe:2.3:a:intel:field_programmable_gate_array_software_development_kit_for_opencl:19.4:*:*:*:pro:*:*:*
EPSS
Процентиль: 25%
0.00087
Низкий
6.7 Medium
CVSS3
7.8 High
CVSS3
Дефекты
CWE-427
CWE-427
Связанные уязвимости
CVSS3: 6.7
github
больше 1 года назад
Uncontrolled search path in some Intel(R) FPGA SDK for OpenCL(TM) software technology may allow an authenticated user to potentially enable escalation of privilege via local access.
CVSS3: 6.7
fstec
почти 2 года назад
Уязвимость программного обеспечения проектирования и разработки Intel FPGA для OpenCL, связанная с неконтролируемым элементом пути поиска, позволяющая нарушителю повысить свои привилегии
EPSS
Процентиль: 25%
0.00087
Низкий
6.7 Medium
CVSS3
7.8 High
CVSS3
Дефекты
CWE-427
CWE-427