Intel Raid Web Console 3 vulnerabilities

6 known vulnerabilities affecting intel/raid_web_console_3.

Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH3MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2020-8688HIGHCVSS 7.5fixed in 7.012.016.0002020-08-13
CVE-2020-8688 [HIGH] CWE-20 CVE-2020-8688: Improper input validation in the Intel(R) RAID Web Console 3 for Windows* may allow an unauthenticat Improper input validation in the Intel(R) RAID Web Console 3 for Windows* may allow an unauthenticated user to potentially enable denial of service via network access.
nvd
CVE-2020-0564HIGHCVSS 7.8fixed in 7.010.009.0002020-02-13
CVE-2020-0564 [HIGH] CWE-276 CVE-2020-0564: Improper permissions in the installer for Intel(R) RWC3 for Windows before version 7.010.009.000 may Improper permissions in the installer for Intel(R) RWC3 for Windows before version 7.010.009.000 may allow an authenticated user to potentially enable escalation of privilege via local access.
nvd
CVE-2019-14601HIGHCVSS 7.8fixed in 7.010.009.0002020-01-17
CVE-2019-14601 [HIGH] CWE-276 CVE-2019-14601: Improper permissions in the installer for Intel(R) RWC 3 for Windows before version 7.010.009.000 ma Improper permissions in the installer for Intel(R) RWC 3 for Windows before version 7.010.009.000 may allow an authenticated user to potentially enable escalation of privilege via local access.
nvd
CVE-2019-11119CRITICALCVSS 9.8≤ 4.1862019-06-13
CVE-2019-11119 [CRITICAL] CVE-2019-11119: Insufficient session validation in the service API for Intel(R) RWC3 version 4.186 and before may al Insufficient session validation in the service API for Intel(R) RWC3 version 4.186 and before may allow an unauthenticated user to potentially enable escalation of privilege via network access.
nvd
CVE-2018-3699MEDIUMCVSS 6.1fixed in 4.1862018-11-14
CVE-2018-3699 [MEDIUM] CWE-79 CVE-2018-3699: Cross-site scripting in the Intel RAID Web Console v3 for Windows may allow an unauthenticated user Cross-site scripting in the Intel RAID Web Console v3 for Windows may allow an unauthenticated user to elevate privilege via remote access.
nvd
CVE-2018-3696MEDIUMCVSS 5.5fixed in 4.1862018-11-14
CVE-2018-3696 [MEDIUM] CWE-287 CVE-2018-3696: Authentication bypass in the Intel RAID Web Console 3 for Windows before 4.186 may allow an unprivil Authentication bypass in the Intel RAID Web Console 3 for Windows before 4.186 may allow an unprivileged user to potentially gain administrative privileges via local access.
nvd