Back to overview

CVE-2024-22476

CRITICAL
10.0
CVSS 3.1
Description
Improper input validation in some Intel(R) Neural Compressor software before version 2.5.0 may allow an unauthenticated user to potentially enable escalation of privilege via remote access.

Metadata

CVE ID
CVE-2024-22476
State
PUBLISHED
Assigner
intel
Reserved
2024-01-13 04:00 UTC
Published
2024-05-16 20:46 UTC
Last updated
2024-08-01 22:51 UTC
Primary CWE
CWE-20
Improper input validation
Vendor / Product
n/a / Intel(R) Neural Compressor software
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
n/a Intel(R) Neural Compressor software before version 2.5.0
Weakness (CWE)
CWESourceDescription
cna escalation of privilege
CWE-20 cna Improper input validation
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
References (1)
Back to overview