CVE-2022-42878

Severity
5.5MEDIUM
EPSS
0.1%
top 70.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 10

Description

Null pointer dereference for some Intel(R) Trace Analyzer and Collector software before version 2021.8.0 published Dec 2022 may allow an authenticated user to potentially enable information disclosure via local access.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:NExploitability: 1.3 | Impact: 1.4

Affected Packages3 packages

CVEListV5intel(r)_trace_analyzer_and_collector_softwarebefore version 2021.8.0 published Dec 2022
NVDintel/oneapi_hpc_toolkit< 2023.0.0

🔴Vulnerability Details

2
CVEList
CVE-2022-42878: Null pointer dereference for some Intel(R) Trace Analyzer and Collector software before version 20212023-05-10
GHSA
GHSA-c8h7-rw5f-pm89: Null pointer dereference for some Intel(R) Trace Analyzer and Collector software before version 20212023-05-10
CVE-2022-42878 (MEDIUM CVSS 5.5) | Null pointer dereference for some I | cvebase.io