CVE-2023-31273
CRITICAL
10.0
CVSS 3.1
Description
Protection mechanism failure in some Intel DCM software before version 5.2 may allow an unauthenticated user to potentially enable escalation of privilege via network access.
Metadata
Severity & Metrics
10.0
CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| n/a | Intel DCM software | — | before version 5.2 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| — | cna | escalation of privilege |
| CWE-693 | cna | Protection mechanism failure |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 10.0 | CRITICAL | 3.1 | cna | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
References (1)
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00902.html https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00902.html