PT-2024-2699 · Intel+1 · Intel Optane Pmem+1

Marius Gabriel Mihai

·

Published

2024-02-13

·

Updated

2024-02-14

·

CVE-2023-27517

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Intel(R) Optane(TM) PMem software versions prior to 01.00.00.3547 Intel(R) Optane(TM) PMem software versions prior to 02.00.00.3915 Intel(R) Optane(TM) PMem software versions prior to 03.00.00.0483
Description The issue is related to improper access control in some Intel(R) Optane(TM) PMem software, which may allow an authenticated user to potentially enable escalation of privilege via local access. This vulnerability affects Intel Optane PMem 100 Series, Intel Optane PMem 200 Series, and Intel Optane PMem 300 Series.
Recommendations For versions prior to 01.00.00.3547, update to version 01.00.00.3547 or later. For versions prior to 02.00.00.3915, update to version 02.00.00.3915 or later. For versions prior to 03.00.00.0483, update to version 03.00.00.0483 or later.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2024-02810
CVE-2023-27517

Affected Products

Debian
Intel Optane Pmem