CVE-2020-12308Sensitive Information Exposure in Intel Computing Improvement Program

3 documents3 sources
Severity
6.5MEDIUMNVD
EPSS
0.3%
top 44.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 12
Latest updateMay 24

Description

Improper access control for the Intel(R) Computing Improvement Program before version 2.4.5982 may allow an unprivileged user to potentially enable information disclosure via network access.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-pp3v-4j93-35vr: Improper access control for the Intel(R) Computing Improvement Program before version 22022-05-24
CVEList
CVE-2020-12308: Improper access control for the Intel(R) Computing Improvement Program before version 22020-11-12
CVE-2020-12308 — Sensitive Information Exposure | cvebase