Vulnerabilidades em Intel

108 resultados
Análise Vexday

Com 108 CVEs catalogadas e nenhuma em exploração ativa confirmada pelo CISA KEV, o perfil de risco da Intel situa-se abaixo da média geral do catálogo, o que indica exposição operacional atualmente contida. No entanto, a presença de 10 vulnerabilidades com prova de conceito pública disponível representa um vetor de atenção relevante, pois facilita tentativas de exploração por atores menos sofisticados. O tipo de falha mais recorrente é CWE-327 — uso de algoritmo criptográfico quebrado ou de risco —, sugerindo que controles relacionados à implementação criptográfica devem ser prioritários nas revisões de hardening. A CVE mais perigosa identificada no conjunto, CVE-2016-8022, apresenta EPSS de 0,13, indicando probabilidade de exploração moderada-baixa, mas ainda merece monitoramento contínuo dado o histórico da classe de vulnerabilidade associada.

CVE-2016-8005File extension filtering vulnerability in Intel Security McAfee Email Gateway (MEG) before 7.6.404h1128596 allows attackers to fail to identEPSS 0.7%CVE-2016-8011Cross-site scripting vulnerability in Intel Security McAfee Endpoint Security (ENS) Web Control before 10.2.0.408.10 allows attackers to injEPSS 0.7%CVE-2023-4334Broadcom RAID Controller Web server (nginx) is serving private files without any authenticationEPSS 0.6%CVE-2015-8987Man-in-the-middle (MitM) attack vulnerability in non-Mac OS agents in McAfee (now Intel Security) Agent (MA) 4.8.0 patch 2 and earlier allowEPSS 0.6%CVE-2023-4332Broadcom RAID Controller web interface is vulnerable due to Improper permissions on the log fileEPSS 0.6%CVE-2023-4335Broadcom RAID Controller Web server (nginx) is serving private server-side files without any authentication on LinuxEPSS 0.6%CVE-2023-4345Broadcom RAID Controller web interface is vulnerable client-side control bypassEPSS 0.6%CVE-2023-4343Broadcom RAID Controller web interface is vulnerable due to exposure of sensitive password information in the URL as a URL search parameterEPSS 0.6%CVE-2020-0549Cleanup errors in some data cache evictions for some Intel(R) Processors may allow an authenticated user to potentially enable information dEPSS 0.6%CVE-2020-0516Improper access control in Intel(R) Graphics Drivers before version 26.20.100.7463 may allow an authenticated user to potentially enable denEPSS 0.6%CVE-2020-0548Cleanup errors in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.EPSS 0.5%CVE-2016-8102Unquoted service path vulnerability in Intel Wireless Bluetooth Drivers 16.x, 17.x, and before 18.1.1607.3129 allows local users to launch pEPSS 0.5%CVE-2016-8026Arbitrary command execution vulnerability in Intel Security McAfee Security Scan Plus (SSP) 3.11.469 and earlier allows authenticated users EPSS 0.5%CVE-2016-8009Privilege escalation vulnerability in Intel Security McAfee Application Control (MAC) 7.0 and 6.x versions allows attackers to cause DoS, unEPSS 0.4%CVE-2013-7461A write protection and execution bypass vulnerability in McAfee (now Intel Security) Change Control (MCC) 6.1.0 for Linux and earlier allowsEPSS 0.4%CVE-2013-7460A write protection and execution bypass vulnerability in McAfee (now Intel Security) Application Control (MAC) 6.1.0 for Linux and earlier aEPSS 0.4%CVE-2016-8105Drivers for the Intel Ethernet Controller X710 and Intel Ethernet Controller XL710 families before version 22.0 are vulnerable to a denial oEPSS 0.4%CVE-2016-8008Privilege escalation vulnerability in Windows 7 and Windows 10 in McAfee Security Scan Plus (SSP) 3.11.376 allows attackers to load a replacEPSS 0.4%CVE-2023-4326Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration that supports obsolete SHA1-based ciphersuitesEPSS 0.4%CVE-2017-5683Privilege escalation in IntelHAXM.sys driver in the Intel Hardware Accelerated Execution Manager before version 6.0.6 allows a local user toEPSS 0.4%