First published: Tue Nov 14 2023(Updated: )
Exposure of sensitive information to an unauthorized actor in firmware for some Intel(R) Optane(TM) SSD products may allow an unauthenticated user to potentially enable information disclosure via physical access.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Intel Optane Memory H20 With Solid State Storage Firmware | <u4110553-g004 | |
Intel Optane Memory H20 With Solid State Storage | ||
All of | ||
Intel Optane Ssd 900p Firmware | <e2010650 | |
Intel Optane Ssd 900p | ||
All of | ||
Intel Optane Ssd Dc P4800x Firmware | <e2010650 | |
Intel Optane Ssd Dc P4800x | ||
All of | ||
Intel Optane Ssd Dc P4801x Firmware | <e2010650 | |
Intel Optane Ssd Dc P4801x | ||
All of | ||
Intel Optane Ssd 905p Firmware | <e2010650 | |
Intel Optane Ssd 905p |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-24588 is a vulnerability that exposes sensitive information to an unauthorized actor in firmware for some Intel(R) Optane(TM) SSD products.
CVE-2023-24588 can occur when an unauthenticated user gains physical access to the affected Intel(R) Optane(TM) SSD products and enables information disclosure.
The severity of CVE-2023-24588 is medium with a CVSS score of 5.9.
CVE-2023-24588 affects firmware for some Intel(R) Optane(TM) SSD products, specifically the Intel Optane Memory H20 With Solid State Storage firmware up to version u4110553-g004 and Intel Optane Ssd 900p Firmware up to version e2010650.
To prevent CVE-2023-24588, ensure that unauthorized users do not have physical access to the affected Intel(R) Optane(TM) SSD products.