Sensitive Information Exposure in Intel Optane SSD Firmware
CVE-2023-24588

5.9MEDIUM

Key Information:

Vendor
Intel
Vendor
CVE Published:
14 November 2023

Summary

A vulnerability in the firmware of specific Intel Optane SSD products could allow an unauthorized actor to access sensitive information if they have physical access to the device. This risk raises concerns as it may enable information disclosure without the need for authentication, posing a significant threat to data security. Users are advised to consult official sources to understand the implications and possible mitigations.

Affected Version(s)

Intel(R) Optane(TM) SSD products firmware for some Intel(R) Optane(TM) SSD products

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.