Uncontrolled Search Path Vulnerability in Intel OpenVINO Toolkit
CVE-2023-28405

6.7MEDIUM

Key Information:

Vendor
Intel
Vendor
CVE Published:
11 August 2023

Summary

The Intel Distribution of OpenVINO Toolkit, prior to version 2022.3.0, contains an uncontrolled search path vulnerability that may allow an authenticated user with local access to execute arbitrary code with escalated privileges. This could lead to significant security risks, especially in environments where sensitive information is processed. Users are urged to upgrade to the latest version to mitigate this issue.

Affected Version(s)

Intel(R) Distribution of OpenVINO(TM) Toolkit before version 2022.3.0

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.