CVE-2023-22841

Unquoted search path in the software installer for the System Firmware Update Utility (SysFwUpdt) for some Intel(R) Server Boards and Intel(R) Server Systems Based on Intel(R) 621A Chipset before version 16.0.7 may allow an authenticated user to potentially enable escalation of privilege via local access.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:intel:server_firmware_update_utility:*:*:*:*:*:*:*:*
cpe:2.3:h:intel:c621a:-:*:*:*:*:*:*:*

History

21 Nov 2024, 07:45

Type Values Removed Values Added
References () http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00830.html - Patch, Vendor Advisory () http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00830.html - Patch, Vendor Advisory
CVSS v2 : unknown
v3 : 7.3
v2 : unknown
v3 : 6.7

23 Aug 2023, 15:45

Type Values Removed Values Added
First Time Intel c621a
Intel server Firmware Update Utility
Intel
CWE CWE-427
CPE cpe:2.3:h:intel:c621a:-:*:*:*:*:*:*:*
cpe:2.3:a:intel:server_firmware_update_utility:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.3
References (MISC) http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00830.html - (MISC) http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00830.html - Patch, Vendor Advisory

11 Aug 2023, 03:44

Type Values Removed Values Added
New CVE

Information

Published : 2023-08-11 03:15

Updated : 2024-11-21 07:45


NVD link : CVE-2023-22841

Mitre link : CVE-2023-22841

CVE.ORG link : CVE-2023-22841


JSON object : View

Products Affected

intel

  • server_firmware_update_utility
  • c621a
CWE
CWE-428

Unquoted Search Path or Element

CWE-427

Uncontrolled Search Path Element