CVE-2020-24485

Improper conditions check in the Intel(R) FPGA OPAE Driver for Linux before kernel version 4.17 may allow an authenticated user to potentially enable escalation of privilege via local access.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:intel:trace_analyzer_and_collector:*:*:*:*:*:*:*:*
cpe:2.3:a:intel:trace_analyzer_and_collector:update1:*:*:*:*:*:*:*
cpe:2.3:a:intel:trace_analyzer_and_collector:update2:*:*:*:*:*:*:*
cpe:2.3:a:intel:trace_analyzer_and_collector:update3:*:*:*:*:*:*:*

History

09 Jun 2021, 19:15

Type Values Removed Values Added
Summary Uncontrolled search path in the Intel(R) Trace Analyzer and Collector before version 2020 update 3 may allow an authenticated user to potentially enable escalation of privilege via local access. Improper conditions check in the Intel(R) FPGA OPAE Driver for Linux before kernel version 4.17 may allow an authenticated user to potentially enable escalation of privilege via local access.
References
  • {'url': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00475.html', 'name': 'https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00475.html', 'tags': ['Patch', 'Vendor Advisory'], 'refsource': 'MISC'}

08 Jun 2021, 19:15

Type Values Removed Values Added
References
  • (CONFIRM) https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00440.html -

23 Feb 2021, 14:59

Type Values Removed Values Added
References (MISC) https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00475.html - (MISC) https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00475.html - Patch, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 4.4
v3 : 7.8
CWE CWE-427
CPE cpe:2.3:a:intel:trace_analyzer_and_collector:update1:*:*:*:*:*:*:*
cpe:2.3:a:intel:trace_analyzer_and_collector:*:*:*:*:*:*:*:*
cpe:2.3:a:intel:trace_analyzer_and_collector:update2:*:*:*:*:*:*:*
cpe:2.3:a:intel:trace_analyzer_and_collector:update3:*:*:*:*:*:*:*

17 Feb 2021, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-02-17 14:15

Updated : 2023-12-10 13:41


NVD link : CVE-2020-24485

Mitre link : CVE-2020-24485

CVE.ORG link : CVE-2020-24485


JSON object : View

Products Affected

intel

  • trace_analyzer_and_collector
CWE
CWE-427

Uncontrolled Search Path Element