Vulnerabilidades en Intel

108 resultados
Análisis Vexday

Com 108 CVEs catalogadas e nenhuma em exploração ativa confirmada pelo CISA KEV, o perfil de risco da Intel situa-se abaixo da média geral do catálogo, o que indica exposição operacional atualmente contida. No entanto, a presença de 10 vulnerabilidades com prova de conceito pública disponível representa um vetor de atenção relevante, pois facilita tentativas de exploração por atores menos sofisticados. O tipo de falha mais recorrente é CWE-327 — uso de algoritmo criptográfico quebrado ou de risco —, sugerindo que controles relacionados à implementação criptográfica devem ser prioritários nas revisões de hardening. A CVE mais perigosa identificada no conjunto, CVE-2016-8022, apresenta EPSS de 0,13, indicando probabilidade de exploração moderada-baixa, mas ainda merece monitoramento contínuo dado o histórico da classe de vulnerabilidade associada.

CVE-2017-3902Cross-site scripting (XSS) vulnerability in the Web user interface (UI) in Intel Security ePO 5.1.3, 5.1.2, 5.1.1, and 5.1.0 allows authentiEPSS 0.7%CVE-2023-4334Broadcom RAID Controller Web server (nginx) is serving private files without any authenticationEPSS 0.6%CVE-2023-4332Broadcom RAID Controller web interface is vulnerable due to Improper permissions on the log fileEPSS 0.6%CVE-2023-4335Broadcom RAID Controller Web server (nginx) is serving private server-side files without any authentication on LinuxEPSS 0.6%CVE-2023-4345Broadcom RAID Controller web interface is vulnerable client-side control bypassEPSS 0.6%CVE-2023-4343Broadcom RAID Controller web interface is vulnerable due to exposure of sensitive password information in the URL as a URL search parameterEPSS 0.6%CVE-2020-0549Cleanup errors in some data cache evictions for some Intel(R) Processors may allow an authenticated user to potentially enable information dEPSS 0.6%CVE-2020-0516Improper access control in Intel(R) Graphics Drivers before version 26.20.100.7463 may allow an authenticated user to potentially enable denEPSS 0.6%CVE-2016-8011Cross-site scripting vulnerability in Intel Security McAfee Endpoint Security (ENS) Web Control before 10.2.0.408.10 allows attackers to injEPSS 0.6%CVE-2020-0548Cleanup errors in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.EPSS 0.5%CVE-2015-8987Man-in-the-middle (MitM) attack vulnerability in non-Mac OS agents in McAfee (now Intel Security) Agent (MA) 4.8.0 patch 2 and earlier allowEPSS 0.5%CVE-2016-8105Drivers for the Intel Ethernet Controller X710 and Intel Ethernet Controller XL710 families before version 22.0 are vulnerable to a denial oEPSS 0.5%CVE-2016-8102Unquoted service path vulnerability in Intel Wireless Bluetooth Drivers 16.x, 17.x, and before 18.1.1607.3129 allows local users to launch pEPSS 0.5%CVE-2016-8026Arbitrary command execution vulnerability in Intel Security McAfee Security Scan Plus (SSP) 3.11.469 and earlier allows authenticated users EPSS 0.4%CVE-2016-8009Privilege escalation vulnerability in Intel Security McAfee Application Control (MAC) 7.0 and 6.x versions allows attackers to cause DoS, unEPSS 0.4%CVE-2023-4326Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration that supports obsolete SHA1-based ciphersuitesEPSS 0.4%CVE-2016-8007Authentication bypass vulnerability in McAfee Host Intrusion Prevention Services (HIPS) 8.0 Patch 7 and earlier allows authenticated users tEPSS 0.4%CVE-2020-0515Uncontrolled search path element in the installer for Intel(R) Graphics Drivers before versions 26.20.100.7584, 15.45.30.5103, 15.40.44.5107EPSS 0.4%CVE-2017-5683Privilege escalation in IntelHAXM.sys driver in the Intel Hardware Accelerated Execution Manager before version 6.0.6 allows a local user toEPSS 0.4%CVE-2016-8008Privilege escalation vulnerability in Windows 7 and Windows 10 in McAfee Security Scan Plus (SSP) 3.11.376 allows attackers to load a replacEPSS 0.4%