CVE-2023-27517: High severity intel optane pmem 100 series management software vulnerability

Published Feb 14, 2024
·
Updated

Improper access control in some Intel(R) Optane(TM) PMem software before versions 01.00.00.3547, 02.00.00.3915, 03.00.00.0483 may allow an athenticated user to potentially enable escalation of privilege via local access.

Affected Software

19 affected components
Intel Optane PMem software<01.00.00.3547, <02.00.00.3915, <03.00.00.0483
All of the following
Intel Optane Persistent Memory Firmware>=01.00.00.3072<01.00.00.3547
Any of the following
Intel Nma1xxd128gpsu4
Intel Nma1xxd128gpsuf
Intel Nma1xxd256gpsu4
Intel Nma1xxd256gpsuf
Intel Nma1xxd512gpsu4
Intel Nma1xxd512gpsuf
All of the following
Intel Optane Persistent Memory Firmware>=02.00.00.3423<02.00.00.3915
Any of the following
Intel Nmb1xxd128gpsu4
Intel Nmb1xxd128gpsuf
Intel Nmb1xxd256gpsu4
Intel Nmb1xxd256gpsuf
Intel Nmb1xxd512gpsu4
Intel Nmb1xxd512gpsuf
All of the following
Intel Optane Persistent Memory Firmware>=03.00.00.0302<03.00.00.0483
Any of the following
Intel Nmc2xxd128gpsu4
Intel Nmc2xxd256gpsu4
Intel Nmc2xxd512gpsu4

Event History

Feb 14, 2024
CVE Published
via MITRE·01:38 PM
Data Sourced
via MITRE·01:38 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Oct 23, 57112
Event
via NVD·10:48 AM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2023-27517?

CVE-2023-27517 is a high-severity vulnerability due to improper access control that may allow privilege escalation for authenticated users.

2

How do I fix CVE-2023-27517?

To fix CVE-2023-27517, upgrade the Intel Optane PMem software to versions 01.00.00.3547, 02.00.00.3915, or 03.00.00.0483 or later.

3

Who is affected by CVE-2023-27517?

CVE-2023-27517 affects Intel Optane PMem software versions prior to 01.00.00.3547, 02.00.00.3915, and 03.00.00.0483.

4

What types of attacks can CVE-2023-27517 enable?

CVE-2023-27517 can potentially enable authenticated users to escalate privileges via local access.

5

Is CVE-2023-27517 related to specific Intel hardware?

CVE-2023-27517 is related to vulnerabilities within the Intel Optane persistent memory firmware used in various Intel hardware configurations.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203