PT-2024-8800 · Intel · Intel Neural Compressor

Published

2024-11-12

·

Updated

2024-11-15

·

CVE-2024-39368

CVSS v4.0

8.6

High

VectorAV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: Intel(R) Neural Compressor versions prior to v3.0
Description: The issue is related to improper neutralization of special elements used in an SQL command, also known as 'SQL Injection', in some Intel(R) Neural Compressor software. This may allow an authenticated user to potentially enable escalation of privilege via adjacent access. The vulnerability can be exploited by a remote attacker to elevate their privileges.
Recommendations: For versions prior to v3.0, upgrade to version v3.0 or later to prevent privilege escalation. As a temporary workaround, consider restricting access to the SQL command functionality until a patch is available. Avoid using the vulnerable software for sensitive operations until the issue is resolved.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2024-10432
CVE-2024-39368

Affected Products

Intel Neural Compressor