Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.1.10.2023.0085
Kategorie:Mageia Linux Local Security Checks
Titel:Mageia: Security Advisory (MGASA-2023-0085)
Zusammenfassung:The remote host is missing an update for the 'microcode' package(s) announced via the MGASA-2023-0085 advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'microcode' package(s) announced via the MGASA-2023-0085 advisory.

Vulnerability Insight:
Updated microcode packages fix security vulnerabilities:

Insufficient granularity of access control in out-of-band management
in some Intel(R) Atom and Intel Xeon Scalable Processors may allow a
privileged user to potentially enable escalation of privilege via
adjacent network access (CVE-2022-21216 / intel-sa-00700).

Incorrect default permissions in some memory controller configurations
for some Intel(R) Xeon(R) Processors when using Intel(R) Software Guard
Extensions which may allow a privileged user to potentially enable
escalation of privilege via local access (CVE-2022-33196 / intel-sa-00738).

Incorrect calculation in microcode keying mechanism for some 3rd
Generation Intel(R) Xeon(R) Scalable Processors may allow a privileged
user to potentially enable information disclosure via local access
(CVE-2022-33972 / intel-sa-00730).

Improper isolation of shared resources in some Intel(R) Processors when
using Intel(R) Software Guard Extensions may allow a privileged user to
potentially enable information disclosure via local access
(CVE-2022-38090 / intel-sa-00767).

Affected Software/OS:
'microcode' package(s) on Mageia 8.

Solution:
Please install the updated package(s).

CVSS Score:
7.2

CVSS Vector:
AV:A/AC:L/Au:M/C:C/I:C/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2022-21216
http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00700.html
Common Vulnerability Exposure (CVE) ID: CVE-2022-33196
http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00738.html
Common Vulnerability Exposure (CVE) ID: CVE-2022-33972
http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00730.html
Common Vulnerability Exposure (CVE) ID: CVE-2022-38090
http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00767.html
CopyrightCopyright (C) 2023 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.