Uncontrolled Search Path Vulnerability in Intel RAID Web Console Software
CVE-2024-34153
7.8HIGH
Summary
A vulnerability exists in Intel RAID Web Console software, which allows an authenticated user to manipulate the search path in an uncontrolled manner. This misconfiguration can potentially lead to privilege escalation through local access. Proper safeguards should be implemented to ensure that authenticated users cannot exploit this vulnerability to gain elevated privileges within the system. Administrators are advised to review security configurations and apply necessary updates or mitigations as recommended by Intel.
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published