CVE-2023-23908
published 2023-08-11CVE-2023-23908: Improper access control in some 3rd Generation Intel(R) Xeon(R) Scalable processors may allow a privileged user to potentially enable information disclosure…
PriorityP416medium4.4CVSS 3.1
AVLACLPRHUINSUCHINAN
EPSS
0.31%
22.7th percentile
Improper access control in some 3rd Generation Intel(R) Xeon(R) Scalable processors may allow a privileged user to potentially enable information disclosure via local access.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | intel-microcode | < intel-microcode 3.20230808.1~deb12u1 (bookworm) | intel-microcode 3.20230808.1~deb12u1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| intel | microcode | < 20230808 | 20230808 |
CVSS provenance
nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
osv6.5MEDIUM
vendor_ubuntu6.5MEDIUM
vendor_debian6.0MEDIUM
vendor_redhat6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Intel Microcode vulnerabilities
vendor_ubuntu·2023-08-14·CVSS 6.5
CVE-2022-40982 [MEDIUM] Intel Microcode vulnerabilities
Title: Intel Microcode vulnerabilities
Summary: Several security issues were fixed in Intel Microcode.
Daniel Moghimi discovered that some Intel(R) Processors did not properly clear
microarchitectural state after speculative execution of various instructions. A
local unprivileged user could use this to obtain to sensitive
information. (CVE-2022-40982)
It was discovered that some Intel(R) Xeon(R) Processors did not properly
restrict error injection for Intel(R) SGX or Intel(R) TDX. A local privileged
user could use this to further escalate their privileges. (CVE-2022-41804)
It was discovered that some 3rd Generation Intel(R) Xeon(R) Scalable processors
did not properly restrict access in some situations. A local privileged attacker
could use this to obtain sensitive information. (CVE-20
Red Hat
hw: Intel: 3rd Generation processors may allow information disclosure
vendor_redhat·2023-08-08·CVSS 6.0
CVE-2023-23908 [MEDIUM] CWE-200 hw: Intel: 3rd Generation processors may allow information disclosure
hw: Intel: 3rd Generation processors may allow information disclosure
Improper access control in some 3rd Generation Intel(R) Xeon(R) Scalable processors may allow a privileged user to potentially enable information disclosure via local access.
An improper access control flaw was found in some third generation Intel processors that may allow a privileged user to enable information disclosure via local access.
Statement: Fixed in microcode_ctl-20230808-1.el9 and microcode_ctl-20220809-2.20230808.2.el8_8
Package: microcode_ctl (Red Hat Enterprise Linux 6) - Will not fix
Package: microcode_ctl (Red Hat Enterprise Linux 7) - Affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Not affected
Package: microcode_ctl (Red Hat
Debian
CVE-2023-23908: intel-microcode - Improper access control in some 3rd Generation Intel(R) Xeon(R) Scalable process...
vendor_debian·2023·CVSS 6.0
CVE-2023-23908 [MEDIUM] CVE-2023-23908: intel-microcode - Improper access control in some 3rd Generation Intel(R) Xeon(R) Scalable process...
Improper access control in some 3rd Generation Intel(R) Xeon(R) Scalable processors may allow a privileged user to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 3.20230808.1~deb12u1)
bullseye: resolved (fixed in 3.20230808.1~deb11u1)
forky: resolved (fixed in 3.20230808.1)
sid: resolved (fixed in 3.20230808.1)
trixie: resolved (fixed in 3.20230808.1)
OSV
intel-microcode vulnerabilities
osv·2023-08-14·CVSS 6.5
CVE-2022-40982 [MEDIUM] intel-microcode vulnerabilities
intel-microcode vulnerabilities
Daniel Moghimi discovered that some Intel(R) Processors did not properly clear
microarchitectural state after speculative execution of various instructions. A
local unprivileged user could use this to obtain to sensitive
information. (CVE-2022-40982)
It was discovered that some Intel(R) Xeon(R) Processors did not properly
restrict error injection for Intel(R) SGX or Intel(R) TDX. A local privileged
user could use this to further escalate their privileges. (CVE-2022-41804)
It was discovered that some 3rd Generation Intel(R) Xeon(R) Scalable processors
did not properly restrict access in some situations. A local privileged attacker
could use this to obtain sensitive information. (CVE-2023-23908)
GHSA
GHSA-4cmv-5jrx-5j4h: Improper access control in some 3rd Generation Intel(R) Xeon(R) Scalable processors may allow a privileged user to potentially enable information disc
ghsa_unreviewed·2023-08-11
CVE-2023-23908 [MEDIUM] CWE-284 GHSA-4cmv-5jrx-5j4h: Improper access control in some 3rd Generation Intel(R) Xeon(R) Scalable processors may allow a privileged user to potentially enable information disc
Improper access control in some 3rd Generation Intel(R) Xeon(R) Scalable processors may allow a privileged user to potentially enable information disclosure via local access.
OSV
CVE-2023-23908: Improper access control in some 3rd Generation Intel(R) Xeon(R) Scalable processors may allow a privileged user to potentially enable information disc
osv·2023-08-11·CVSS 4.4
CVE-2023-23908 [MEDIUM] CVE-2023-23908: Improper access control in some 3rd Generation Intel(R) Xeon(R) Scalable processors may allow a privileged user to potentially enable information disc
Improper access control in some 3rd Generation Intel(R) Xeon(R) Scalable processors may allow a privileged user to potentially enable information disclosure via local access.
No detection rules found.
No public exploits indexed.
http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00836.htmlhttps://lists.debian.org/debian-lts-announce/2023/08/msg00026.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/HKREYYTWUY7ZDNIB2N6H5BUJ3LE5VZPE/https://lists.fedoraproject.org/archives/list/[email protected]/message/OL7WI2TJCWSZIQP2RIOLWHOKLM25M44J/https://security.netapp.com/advisory/ntap-20230824-0003/https://www.debian.org/security/2023/dsa-5474http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00836.htmlhttps://lists.debian.org/debian-lts-announce/2023/08/msg00026.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/HKREYYTWUY7ZDNIB2N6H5BUJ3LE5VZPE/https://lists.fedoraproject.org/archives/list/[email protected]/message/OL7WI2TJCWSZIQP2RIOLWHOKLM25M44J/https://security.netapp.com/advisory/ntap-20230824-0003/https://www.debian.org/security/2023/dsa-5474
2023-08-11
Published