Vulnerabilidades em Intel

108 resultados
Análise Vexday

Com 108 CVEs catalogadas e nenhuma em exploração ativa confirmada pelo CISA KEV, o perfil de risco da Intel situa-se abaixo da média geral do catálogo, o que indica exposição operacional atualmente contida. No entanto, a presença de 10 vulnerabilidades com prova de conceito pública disponível representa um vetor de atenção relevante, pois facilita tentativas de exploração por atores menos sofisticados. O tipo de falha mais recorrente é CWE-327 — uso de algoritmo criptográfico quebrado ou de risco —, sugerindo que controles relacionados à implementação criptográfica devem ser prioritários nas revisões de hardening. A CVE mais perigosa identificada no conjunto, CVE-2016-8022, apresenta EPSS de 0,13, indicando probabilidade de exploração moderada-baixa, mas ainda merece monitoramento contínuo dado o histórico da classe de vulnerabilidade associada.

CVE-2020-0551Load value injection in some Intel(R) Processors utilizing speculative execution may allow an authenticated user to potentially enable inforEPSS 1.0%CVE-2018-10932MEDIUMlldptool version 1.0.1 and older can print a raw, unsanitized attacker controlled buffer when mngAddr information is displayed. This may allEPSS 1.0%CVE-2015-8990Detection bypass vulnerability in Intel Security Advanced Threat Defense (ATD) 3.4.6 and earlier allows malware samples to bypass ATD detectEPSS 1.0%CVE-2015-8986Sandbox detection evasion vulnerability in hardware appliances in McAfee (now Intel Security) Advanced Threat Defense (MATD) 3.4.2.32 and eaEPSS 0.9%CVE-2015-8988Unquoted executable path vulnerability in Client Management and Gateway components in McAfee (now Intel Security) ePO Deep Command (eDC) 2.2EPSS 0.9%CVE-2023-4339Broadcom RAID Controller web interface is vulnerable to exposure of private keys used for CIM stored with insecure file permissionsEPSS 0.8%CVE-2017-3902Cross-site scripting (XSS) vulnerability in the Web user interface (UI) in Intel Security ePO 5.1.3, 5.1.2, 5.1.1, and 5.1.0 allows authentiEPSS 0.8%CVE-2015-8989Unsalted password vulnerability in the Enterprise Manager (web portal) component in Intel Security McAfee Vulnerability Manager (MVM) 7.5.8 EPSS 0.8%CVE-2024-3411CRITICALInsufficient Randomness When Validating an IPMI Authenticated SessionEPSS 0.7%CVE-2023-4323Broadcom RAID Controller web interface is vulnerable to improper session management of active sessions on Gateway setupEPSS 0.7%CVE-2023-4344CRITICALBroadcom RAID Controller web interface is vulnerable to insufficient randomness due to improper use of ssl.rnd to setup CIM connectionEPSS 0.7%CVE-2023-4341Broadcom RAID Controller is vulnerable to Privilege escalation to root due to creation of insecure folders by Web GUIEPSS 0.7%CVE-2023-4324Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP Content-Security-Policy headersEPSS 0.7%CVE-2023-4329Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safeguard SESSIONID cookie with SameSite attributeEPSS 0.7%CVE-2023-4340Broadcom RAID Controller is vulnerable to Privilege escalation by taking advantage of the Session prints in the log fileEPSS 0.7%CVE-2023-4337Broadcom RAID Controller web interface is vulnerable to improper session handling of managed servers on Gateway installationEPSS 0.7%CVE-2023-4336Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safeguard cookies with Secure attributeEPSS 0.7%CVE-2023-4338Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not provide X-Content-Type-Options HeadersEPSS 0.7%CVE-2023-4325Broadcom RAID Controller web interface is vulnerable due to usage of Libcurl with LSA has known vulnerabilitiesEPSS 0.7%CVE-2023-4342Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP strict-transport-security policyEPSS 0.7%