Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.1.10.2023.0085
Categoría:Mageia Linux Local Security Checks
Título:Mageia: Security Advisory (MGASA-2023-0085)
Resumen:The remote host is missing an update for the 'microcode' package(s) announced via the MGASA-2023-0085 advisory.
Descripción:Summary:
The remote host is missing an update for the 'microcode' package(s) announced via the MGASA-2023-0085 advisory.

Vulnerability Insight:
Updated microcode packages fix security vulnerabilities:

Insufficient granularity of access control in out-of-band management
in some Intel(R) Atom and Intel Xeon Scalable Processors may allow a
privileged user to potentially enable escalation of privilege via
adjacent network access (CVE-2022-21216 / intel-sa-00700).

Incorrect default permissions in some memory controller configurations
for some Intel(R) Xeon(R) Processors when using Intel(R) Software Guard
Extensions which may allow a privileged user to potentially enable
escalation of privilege via local access (CVE-2022-33196 / intel-sa-00738).

Incorrect calculation in microcode keying mechanism for some 3rd
Generation Intel(R) Xeon(R) Scalable Processors may allow a privileged
user to potentially enable information disclosure via local access
(CVE-2022-33972 / intel-sa-00730).

Improper isolation of shared resources in some Intel(R) Processors when
using Intel(R) Software Guard Extensions may allow a privileged user to
potentially enable information disclosure via local access
(CVE-2022-38090 / intel-sa-00767).

Affected Software/OS:
'microcode' package(s) on Mageia 8.

Solution:
Please install the updated package(s).

CVSS Score:
7.2

CVSS Vector:
AV:A/AC:L/Au:M/C:C/I:C/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2022-21216
http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00700.html
Common Vulnerability Exposure (CVE) ID: CVE-2022-33196
http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00738.html
Common Vulnerability Exposure (CVE) ID: CVE-2022-33972
http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00730.html
Common Vulnerability Exposure (CVE) ID: CVE-2022-38090
http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00767.html
CopyrightCopyright (C) 2023 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.