First published: Wed Feb 17 2021(Updated: )
Improper conditions check in the Intel(R) FPGA OPAE Driver for Linux before kernel version 4.17 may allow an authenticated user to potentially enable escalation of privilege via local access.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel Trace Analyzer and Collector | <2020 | |
Intel Trace Analyzer and Collector | =update1 | |
Intel Trace Analyzer and Collector | =update2 | |
Intel Trace Analyzer and Collector | =update3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-24485 is a vulnerability in the Intel FPGA OPAE Driver for Linux before kernel version 4.17 that may allow an authenticated user to potentially enable escalation of privilege via local access.
CVE-2020-24485 has a severity rating of 7.8, which is considered high.
Intel Trace Analyzer and Collector versions up to and including 2020, update1, update2, and update3 are affected by CVE-2020-24485.
An authenticated user with local access can exploit CVE-2020-24485 to potentially enable escalation of privilege.
For more information about CVE-2020-24485, you can refer to the advisory provided by Intel at the following URL: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00440.html