CVE-2023-23909: Medium severity intel oneapi hpc toolkit vulnerability
Out-of-bounds read for some Intel(R) Trace Analyzer and Collector software before version 2021.8.0 published Dec 2022 may allow an authenticated user to potentially enable information disclosure via local access.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-23909?
CVE-2023-23909 is a vulnerability in some Intel(R) Trace Analyzer and Collector software that allows an authenticated user to potentially enable information disclosure via local access.
How severe is CVE-2023-23909?
CVE-2023-23909 has a severity rating of medium (5.5).
Which software versions are affected by CVE-2023-23909?
CVE-2023-23909 affects Intel(R) Trace Analyzer and Collector software versions before 2021.8.0 published in Dec 2022.
How can an authenticated user exploit CVE-2023-23909?
An authenticated user can potentially enable information disclosure via local access in Intel(R) Trace Analyzer and Collector software before version 2021.8.0.
Is there a fix for CVE-2023-23909?
Yes, the fix for CVE-2023-23909 is to upgrade to version 2021.8.0 or later of Intel(R) Trace Analyzer and Collector software.