ID

VAR-201809-0140


CVE

CVE-2018-12175


TITLE

Intel Distribution for Python Vulnerabilities related to authorization, permissions, and access control

Trust: 0.8

sources: JVNDB: JVNDB-2018-010520

DESCRIPTION

Default install directory permissions in Intel Distribution for Python (IDP) version 2018 may allow an unprivileged user to escalate privileges via local access. Intel Distribution for Python (IDP) is a software package from Intel Corporation to enhance Python applications and accelerate core computing. A security vulnerability exists in the Intel IDP 2018 release

Trust: 1.71

sources: NVD: CVE-2018-12175 // JVNDB: JVNDB-2018-010520 // VULHUB: VHN-122108

AFFECTED PRODUCTS

vendor:intelmodel:distribution for pythonscope:eqversion:2018

Trust: 2.4

sources: JVNDB: JVNDB-2018-010520 // CNNVD: CNNVD-201809-610 // NVD: CVE-2018-12175

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-12175
value: HIGH

Trust: 1.0

NVD: CVE-2018-12175
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201809-610
value: HIGH

Trust: 0.6

VULHUB: VHN-122108
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2018-12175
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-122108
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-12175
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-122108 // JVNDB: JVNDB-2018-010520 // CNNVD: CNNVD-201809-610 // NVD: CVE-2018-12175

PROBLEMTYPE DATA

problemtype:CWE-276

Trust: 1.1

problemtype:CWE-264

Trust: 0.9

sources: VULHUB: VHN-122108 // JVNDB: JVNDB-2018-010520 // NVD: CVE-2018-12175

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-201809-610

TYPE

permissions and access control issues

Trust: 0.6

sources: CNNVD: CNNVD-201809-610

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-010520

PATCH

title:INTEL-SA-00181url:https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00181.html

Trust: 0.8

title:Intel Distribution for Python Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=84869

Trust: 0.6

sources: JVNDB: JVNDB-2018-010520 // CNNVD: CNNVD-201809-610

EXTERNAL IDS

db:NVDid:CVE-2018-12175

Trust: 2.5

db:JVNDBid:JVNDB-2018-010520

Trust: 0.8

db:CNNVDid:CNNVD-201809-610

Trust: 0.7

db:CNVDid:CNVD-2020-18576

Trust: 0.1

db:VULHUBid:VHN-122108

Trust: 0.1

sources: VULHUB: VHN-122108 // JVNDB: JVNDB-2018-010520 // CNNVD: CNNVD-201809-610 // NVD: CVE-2018-12175

REFERENCES

url:https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00181.html

Trust: 1.7

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-12175

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2018-12175

Trust: 0.8

sources: VULHUB: VHN-122108 // JVNDB: JVNDB-2018-010520 // CNNVD: CNNVD-201809-610 // NVD: CVE-2018-12175

SOURCES

db:VULHUBid:VHN-122108
db:JVNDBid:JVNDB-2018-010520
db:CNNVDid:CNNVD-201809-610
db:NVDid:CVE-2018-12175

LAST UPDATE DATE

2024-11-23T21:52:50.771000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-122108date:2019-10-03T00:00:00
db:JVNDBid:JVNDB-2018-010520date:2018-12-17T00:00:00
db:CNNVDid:CNNVD-201809-610date:2019-10-23T00:00:00
db:NVDid:CVE-2018-12175date:2024-11-21T03:44:42.017

SOURCES RELEASE DATE

db:VULHUBid:VHN-122108date:2018-09-12T00:00:00
db:JVNDBid:JVNDB-2018-010520date:2018-12-17T00:00:00
db:CNNVDid:CNNVD-201809-610date:2018-09-13T00:00:00
db:NVDid:CVE-2018-12175date:2018-09-12T19:29:02.107