CVE-2023-23909

CWE-125Out-of-bounds Read3 documents3 sources
Severity
5.5MEDIUM
EPSS
0.1%
top 70.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 10

Description

Out-of-bounds read for some Intel(R) Trace Analyzer and Collector software before version 2021.8.0 published Dec 2022 may allow an authenticated user to potentially enable information disclosure via local access.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:NExploitability: 1.3 | Impact: 1.4

Affected Packages3 packages

CVEListV5intel(r)_trace_analyzer_and_collector_softwarebefore version 2021.8.0 published Dec 2022
NVDintel/oneapi_hpc_toolkit< 2023.0.0

🔴Vulnerability Details

2
CVEList
CVE-2023-23909: Out-of-bounds read for some Intel(R) Trace Analyzer and Collector software before version 20212023-05-10
GHSA
GHSA-96j5-rxm2-2j66: Out-of-bounds read for some Intel(R) Trace Analyzer and Collector software before version 20212023-05-10
CVE-2023-23909 (MEDIUM CVSS 5.5) | Out-of-bounds read for some Intel(R | cvebase.io