PT-2024-7677 · Intel · Intel Raid Web Console

Marius Gabriel Mihai

·

Published

2024-09-16

·

Updated

2024-10-09

·

CVE-2024-34153

CVSS v3.1

6.7

Medium

VectorAV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Intel(R) RAID Web Console software for all versions
Description The issue is related to an uncontrolled search path element in the Intel(R) RAID Web Console software. This may allow an authenticated user to potentially enable escalation of privilege via local access.
Recommendations For all versions, consider restricting local access to the Intel(R) RAID Web Console software until a fix is available. As a temporary workaround, review and limit the search path elements to prevent potential exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Uncontrolled Search Path Element

Weakness Enumeration

Related Identifiers

BDU:2024-09123
CVE-2024-34153

Affected Products

Intel Raid Web Console