CVE-2019-0108
published 2019-02-18CVE-2019-0108: Improper file permissions for Intel(R) Data Center Manager SDK before version 5.0.2 may allow an authenticated user to potentially enable disclosure of…
PriorityP421medium5.5CVSS 3.0
AVLACLPRLUINSUCHINAN
EPSS
0.41%
32.9th percentile
Improper file permissions for Intel(R) Data Center Manager SDK before version 5.0.2 may allow an authenticated user to potentially enable disclosure of information via local access.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| intel | data_center_manager | < 5.0.2 | 5.0.2 |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vvch-684v-5f39: Improper file permissions for Intel(R) Data Center Manager SDK before version 5
ghsa_unreviewed·2022-05-13
CVE-2019-0108 [MEDIUM] CWE-732 GHSA-vvch-684v-5f39: Improper file permissions for Intel(R) Data Center Manager SDK before version 5
Improper file permissions for Intel(R) Data Center Manager SDK before version 5.0.2 may allow an authenticated user to potentially enable disclosure of information via local access.
CISA ICS
Intel Data Center Manager SDK
cisa_ics·2019-02-19·CVSS 8.8
[HIGH] Intel Data Center Manager SDK
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Intel Data Center Manager SDK
Last RevisedFebruary 19, 2019
Alert CodeICSA-19-050-01
## 1. EXECUTIVE SUMMARY
-
CVSS v3 8.8
- ATTENTION: Exploitable remotely/low skill level to exploit
- Vendor: Intel
- Equipment: Data Center Manager SDK
- Vulnerabilities: Improper Authentication, Protection Mechanism Failure, Permission Issues, Key Management Errors, Insufficient Control Flow Management
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities may allow escalation of privilege, denial of service, or information disclosure.
## 3. TECHNICAL DETAILS
## 3.1 AFFE
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/107075https://ics-cert.us-cert.gov/advisories/ICSA-19-050-01https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00215.htmlhttp://www.securityfocus.com/bid/107075https://ics-cert.us-cert.gov/advisories/ICSA-19-050-01https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00215.html
2019-02-18
Published