VDB

CVE-2023-28389

CVE-2023-28389 PUBLISHED

Es existiert eine Schwachstelle in Intel Chipset Software. In Intel CSME-Installationssoftware werden falsche Standardberechtigungen gesetzt. Ein lokaler Angreifer kann diese Schwachstelle ausnutzen, um seine Privilegien zu erweitern.

EPSS 0.03% · 8.4th percentile

Risk Scores

EPSS Score
0.03%
8.4th percentile

Affected Products

VendorProductVersions
DellDell PowerEdge T30/T40 Mini Tower
IntelIntel Chipset LMS <2316.5.1.2
LenovoLenovo Computer
DellDell Computer
HPHP Computer
IntelIntel Chipset CSME installer <2328.5.5.0
DellDell PowerEdge

Timeline

  • Jun 28, 2021 PoC Published
  • Dec 11, 2021 PoC Published
  • Dec 13, 2021 PoC Published
  • Dec 18, 2021 PoC Published
  • Jun 7, 2022 PoC Published
  • Sep 16, 2022 PoC Published
  • Nov 21, 2023 PoC Published
  • Dec 8, 2023 PoC Published
  • Dec 11, 2023 PoC Published
  • Mar 1, 2024 PoC Published
  • Mar 12, 2024 CVE Published
  • Mar 15, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›