CVE-2023-28388
published 2023-11-14CVE-2023-28388: Uncontrolled search path element in some Intel(R) Chipset Device Software before version 10.1.19444.8378 may allow an authenticated user to potentially enable…
PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.19%
9.0th percentile
Uncontrolled search path element in some Intel(R) Chipset Device Software before version 10.1.19444.8378 may allow an authenticated user to potentially enable escalation of privilege via local access.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| intel | chipset_device_software | < 10.1.19444.8378 | 10.1.19444.8378 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Hitachi Energy MACH PS700
cisa_ics·2025-03-04·CVSS 6.7
[MEDIUM] Hitachi Energy MACH PS700
ICS Advisory
##
Hitachi Energy MACH PS700
Release DateMarch 04, 2025
Alert CodeICSA-25-063-03
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 6.7
- ATTENTION:
- Vendor: Hitachi Energy
- Equipment: MACH PS700
- Vulnerability: Uncontrolled Search Path Element
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow an attacker to escalate privileges and gain control over the software.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Hitachi Energy reports the following products are affected:
- MACH PS700: Version v2
## 3.2 VULNERABILITY OVERVIEW
## 3.2.1 UNCONTROLLED SEARCH PATH ELEMENT CWE-427
Uncontrolled search path element in some Intel(R) C
GHSA
GHSA-4384-whxj-38x3: Uncontrolled search path element in some Intel(R) Chipset Device Software before version 10
ghsa_unreviewed·2023-11-14
CVE-2023-28388 [MEDIUM] CWE-427 GHSA-4384-whxj-38x3: Uncontrolled search path element in some Intel(R) Chipset Device Software before version 10
Uncontrolled search path element in some Intel(R) Chipset Device Software before version 10.1.19444.8378 may allow an authenticated user to potentially enable escalation of privilege via local access.
No detection rules found.
No public exploits indexed.
2023-11-14
Published