First published: Wed Feb 14 2024(Updated: )
Improper access control in some Intel(R) Optane(TM) PMem software before versions 01.00.00.3547, 02.00.00.3915, 03.00.00.0483 may allow an athenticated user to potentially enable escalation of privilege via local access.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel Optane PMem 100 Series Management Software | <01.00.00.3547<02.00.00.3915<03.00.00.0483 | |
All of | ||
Intel Optane Persistent Memory Firmware | >=01.00.00.3072<01.00.00.3547 | |
Any of | ||
Intel NMA1xxD128GPSU4 | ||
Intel NMA1xxD128GPSU4 | ||
Intel NMA1xxD256GPSU4 | ||
Intel NMA1XXD256GPSUF | ||
Intel NMB1XXD512GPSUF | ||
Intel NMB1XXD512GPSUF | ||
All of | ||
Intel Optane Persistent Memory Firmware | >=02.00.00.3423<02.00.00.3915 | |
Any of | ||
Intel Nmc2xxd128gpsu4 | ||
Intel NMB1XXD128GPSUF | ||
Intel NMA1xxD256GPSU4 | ||
Intel Nmb1xxd256gpsuf | ||
Intel NMB1xxD512GPSU4 | ||
Intel NMB1xxD512GPSU4 | ||
All of | ||
Intel Optane Persistent Memory Firmware | >=03.00.00.0302<03.00.00.0483 | |
Any of | ||
Intel Nmc2xxd128gpsu4 | ||
Intel Nmc2xxd256gpsu4 | ||
Intel Nmc2xxd512gpsu4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-27517 is a high-severity vulnerability due to improper access control that may allow privilege escalation for authenticated users.
To fix CVE-2023-27517, upgrade the Intel Optane PMem software to versions 01.00.00.3547, 02.00.00.3915, or 03.00.00.0483 or later.
CVE-2023-27517 affects Intel Optane PMem software versions prior to 01.00.00.3547, 02.00.00.3915, and 03.00.00.0483.
CVE-2023-27517 can potentially enable authenticated users to escalate privileges via local access.
CVE-2023-27517 is related to vulnerabilities within the Intel Optane persistent memory firmware used in various Intel hardware configurations.