Vulnerability Description
Improper access control in some 3rd Generation Intel(R) Xeon(R) Scalable processors may allow a privileged user to potentially enable information disclosure via local access.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Intel | Microcode | < 20230808 |
| Intel | Xeon D-1513N | - |
| Intel | Xeon D-1518 | - |
| Intel | Xeon D-1520 | - |
| Intel | Xeon D-1521 | - |
| Intel | Xeon D-1523N | - |
| Intel | Xeon D-1527 | - |
| Intel | Xeon D-1528 | - |
| Intel | Xeon D-1529 | - |
| Intel | Xeon D-1531 | - |
| Intel | Xeon D-1533N | - |
| Intel | Xeon D-1537 | - |
| Intel | Xeon D-1539 | - |
| Intel | Xeon D-1540 | - |
| Intel | Xeon D-1541 | - |
| Intel | Xeon D-1543N | - |
| Intel | Xeon D-1548 | - |
| Intel | Xeon D-1553N | - |
| Intel | Xeon D-1557 | - |
| Intel | Xeon D-1559 | - |
Related Weaknesses (CWE)
References
- http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00836.hVendor Advisory
- https://lists.debian.org/debian-lts-announce/2023/08/msg00026.htmlMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/[email protected]Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/[email protected]Mailing ListThird Party Advisory
- https://security.netapp.com/advisory/ntap-20230824-0003/
- https://www.debian.org/security/2023/dsa-5474Third Party Advisory
- http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00836.hVendor Advisory
- https://lists.debian.org/debian-lts-announce/2023/08/msg00026.htmlMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/[email protected]Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/[email protected]Mailing ListThird Party Advisory
- https://security.netapp.com/advisory/ntap-20230824-0003/
- https://www.debian.org/security/2023/dsa-5474Third Party Advisory
FAQ
What is CVE-2023-23908?
CVE-2023-23908 is a vulnerability with a CVSS score of 6.0 (MEDIUM). Improper access control in some 3rd Generation Intel(R) Xeon(R) Scalable processors may allow a privileged user to potentially enable information disclosure via local access.
How severe is CVE-2023-23908?
CVE-2023-23908 has been rated MEDIUM with a CVSS base score of 6.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-23908?
Check the references section above for vendor advisories and patch information. Affected products include: Intel Microcode, Intel Xeon D-1513N, Intel Xeon D-1518, Intel Xeon D-1520, Intel Xeon D-1521.