Insufficient Control Flow Management in Intel IPP Cryptography Software
CVE-2022-37409
4.7MEDIUM
Summary
The Intel IPP Cryptography software, prior to version 2021.6, suffers from insufficient control flow management. This vulnerability could potentially allow an authenticated user to gain access to sensitive information through local access. It highlights a critical aspect of software security that can lead to significant privacy concerns if exploited.
Affected Version(s)
Intel(R) IPP Cryptography software before version 2021.6
References
CVSS V3.1
Score:
4.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved