Intel Virtual Raid On Cpu vulnerabilities

12 known vulnerabilities affecting intel/virtual_raid_on_cpu.

Total CVEs
12
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH8MEDIUM3LOW1

Vulnerabilities

Page 1 of 1
CVE-2024-29079MEDIUMCVSS 6.9fixed in 8.6.0.30012024-11-13
CVE-2024-29079 [MEDIUM] CWE-691 CVE-2024-29079: Insufficient control flow management in some Intel(R) VROC software before version 8.6.0.3001 may al Insufficient control flow management in some Intel(R) VROC software before version 8.6.0.3001 may allow an authenticated user to potentially enable escalation of privilege via local access.
nvd
CVE-2024-32485LOWCVSS 2.4fixed in 8.6.0.20032024-11-13
CVE-2024-32485 [LOW] CWE-20 CVE-2024-32485: Improper Input Validation in some Intel(R) VROC software before version 8.6.0.2003 may allow an auth Improper Input Validation in some Intel(R) VROC software before version 8.6.0.2003 may allow an authenticated user to potentially enable denial of service via local access.
nvd
CVE-2024-23489MEDIUMCVSS 5.4fixed in 8.6.0.11912024-08-14
CVE-2024-23489 [MEDIUM] CWE-427 CVE-2024-23489: Uncontrolled search path for some Intel(R) VROC software before version 8.6.0.1191 may allow an auth Uncontrolled search path for some Intel(R) VROC software before version 8.6.0.1191 may allow an authenticated user to potentially enable escalation of privilege via local access.
nvd
CVE-2023-35003HIGHCVSS 7.8fixed in 8.0.8.10012024-02-14
CVE-2023-35003 [MEDIUM] CWE-249 CVE-2023-35003: Path transversal in some Intel(R) VROC software before version 8.0.8.1001 may allow an authenticated Path transversal in some Intel(R) VROC software before version 8.0.8.1001 may allow an authenticated user to potentially enable escalation of privilege via local access.
nvd
CVE-2023-32646HIGHCVSS 7.3fixed in 8.0.8.10012024-02-14
CVE-2023-32646 [MEDIUM] CWE-427 CVE-2023-32646: Uncontrolled search path element in some Intel(R) VROC software before version 8.0.8.1001 may allow Uncontrolled search path element in some Intel(R) VROC software before version 8.0.8.1001 may allow an authenticated user to potentially enable escalation of privilege via local access.
nvd
CVE-2023-34315HIGHCVSS 7.8fixed in 8.0.8.10012024-02-14
CVE-2023-34315 [MEDIUM] CWE-276 CVE-2023-34315: Incorrect default permissions in some Intel(R) VROC software before version 8.0.8.1001 may allow an Incorrect default permissions in some Intel(R) VROC software before version 8.0.8.1001 may allow an authenticated user to potentially enable escalation of privilege via local access.
nvd
CVE-2023-31271HIGHCVSS 7.8fixed in 8.0.8.10012024-02-14
CVE-2023-31271 [MEDIUM] CWE-284 CVE-2023-31271: Improper access control in some Intel(R) VROC software before version 8.0.8.1001 may allow an authen Improper access control in some Intel(R) VROC software before version 8.0.8.1001 may allow an authenticated user to potentially enable escalation of privilege via local access.
nvd
CVE-2022-45112HIGHCVSS 7.8fixed in 8.0.0.40352023-08-11
CVE-2022-45112 [HIGH] CWE-284 CVE-2022-45112: Improper access control in some Intel(R) VROC software before version 8.0.0.4035 may allow an authen Improper access control in some Intel(R) VROC software before version 8.0.0.4035 may allow an authenticated user to potentially enable escalation of privilege via local access.
nvd
CVE-2022-30338HIGHCVSS 7.8fixed in 7.7.6.10032023-05-10
CVE-2022-30338 [MEDIUM] CWE-276 CVE-2022-30338: Incorrect default permissions in the Intel(R) VROC software before version 7.7.6.1003 may allow an a Incorrect default permissions in the Intel(R) VROC software before version 7.7.6.1003 may allow an authenticated user to potentially enable escalation of privilege via local access.
nvd
CVE-2022-29508HIGHCVSS 7.8fixed in 7.7.6.10032023-05-10
CVE-2022-29508 [MEDIUM] CWE-395 CVE-2022-29508: Null pointer dereference in the Intel(R) VROC software before version 7.7.6.1003 may allow an authen Null pointer dereference in the Intel(R) VROC software before version 7.7.6.1003 may allow an authenticated user to potentially enable escalation of privilege via local access.
nvd
CVE-2022-29919HIGHCVSS 7.8fixed in 7.7.6.10032023-05-10
CVE-2022-29919 [HIGH] CWE-416 CVE-2022-29919: Use after free in the Intel(R) VROC software before version 7.7.6.1003 may allow an authenticated us Use after free in the Intel(R) VROC software before version 7.7.6.1003 may allow an authenticated user to potentially enable escalation of privilege via local access.
nvd
CVE-2022-25976MEDIUMCVSS 5.5fixed in 7.7.6.10032023-05-10
CVE-2022-25976 [MEDIUM] CWE-20 CVE-2022-25976: Improper input validation in the Intel(R) VROC software before version 7.7.6.1003 may allow an authe Improper input validation in the Intel(R) VROC software before version 7.7.6.1003 may allow an authenticated user to potentially enable denial of service via local access.
nvd