ID

VAR-201902-0789


CVE

CVE-2019-0101


TITLE

Intel(R) Unite Vulnerabilities related to authorization, permissions, and access control

Trust: 0.8

sources: JVNDB: JVNDB-2019-001858

DESCRIPTION

Authentication bypass in the Intel Unite(R) solution versions 3.2 through 3.3 may allow an unauthenticated user to potentially enable escalation of privilege to the Intel Unite(R) Solution administrative portal via network access. Intel(R) Unite Contains vulnerabilities related to authorization, permissions, and access control.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Intel Unite App is prone to a privilege-escalation vulnerability. A remote attacker can exploit this issue to gain elevated privileges. Intel Unite App 3.2 through 3.3. are vulnerable. Intel Unite is an enterprise conference collaboration solution developed by Intel Corporation of the United States. A security vulnerability exists in the management portal in Intel Unite(R) versions 3.2 to 3.3

Trust: 1.98

sources: NVD: CVE-2019-0101 // JVNDB: JVNDB-2019-001858 // BID: 107076 // VULHUB: VHN-140132

AFFECTED PRODUCTS

vendor:intelmodel:unitescope:lteversion:3.3

Trust: 1.0

vendor:intelmodel:unitescope:gteversion:3.2

Trust: 1.0

vendor:intelmodel:unitescope:eqversion:3.2 to 3.3

Trust: 0.8

vendor:intelmodel:unite appscope:eqversion:3.3

Trust: 0.3

vendor:intelmodel:unite appscope:eqversion:3.2

Trust: 0.3

vendor:intelmodel:unite appscope:neversion:3.3.163

Trust: 0.3

vendor:intelmodel:unite appscope:neversion:3.2.91

Trust: 0.3

sources: BID: 107076 // JVNDB: JVNDB-2019-001858 // NVD: CVE-2019-0101

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2019-0101
value: CRITICAL

Trust: 1.0

NVD: CVE-2019-0101
value: CRITICAL

Trust: 0.8

CNNVD: CNNVD-201902-702
value: CRITICAL

Trust: 0.6

VULHUB: VHN-140132
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2019-0101
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-140132
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2019-0101
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-140132 // JVNDB: JVNDB-2019-001858 // CNNVD: CNNVD-201902-702 // NVD: CVE-2019-0101

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:CWE-264

Trust: 0.9

sources: VULHUB: VHN-140132 // JVNDB: JVNDB-2019-001858 // NVD: CVE-2019-0101

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201902-702

TYPE

permissions and access control

Trust: 0.6

sources: CNNVD: CNNVD-201902-702

CONFIGURATIONS

sources: JVNDB: JVNDB-2019-001858

PATCH

title:INTEL-SA-00214url:https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00214.html

Trust: 0.8

title:Intel Unite Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=89524

Trust: 0.6

sources: JVNDB: JVNDB-2019-001858 // CNNVD: CNNVD-201902-702

EXTERNAL IDS

db:NVDid:CVE-2019-0101

Trust: 2.8

db:BIDid:107076

Trust: 2.0

db:JVNDBid:JVNDB-2019-001858

Trust: 0.8

db:CNNVDid:CNNVD-201902-702

Trust: 0.7

db:VULHUBid:VHN-140132

Trust: 0.1

sources: VULHUB: VHN-140132 // BID: 107076 // JVNDB: JVNDB-2019-001858 // CNNVD: CNNVD-201902-702 // NVD: CVE-2019-0101

REFERENCES

url:http://www.securityfocus.com/bid/107076

Trust: 2.3

url:https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00214.html

Trust: 2.0

url:https://nvd.nist.gov/vuln/detail/cve-2019-0101

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-0101

Trust: 0.8

url:http://www.intel.com/

Trust: 0.3

sources: VULHUB: VHN-140132 // BID: 107076 // JVNDB: JVNDB-2019-001858 // CNNVD: CNNVD-201902-702 // NVD: CVE-2019-0101

CREDITS

The vendor reported this issue.

Trust: 0.9

sources: BID: 107076 // CNNVD: CNNVD-201902-702

SOURCES

db:VULHUBid:VHN-140132
db:BIDid:107076
db:JVNDBid:JVNDB-2019-001858
db:CNNVDid:CNNVD-201902-702
db:NVDid:CVE-2019-0101

LAST UPDATE DATE

2024-11-23T22:30:08.372000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-140132date:2020-08-24T00:00:00
db:BIDid:107076date:2019-02-12T00:00:00
db:JVNDBid:JVNDB-2019-001858date:2019-03-27T00:00:00
db:CNNVDid:CNNVD-201902-702date:2020-08-25T00:00:00
db:NVDid:CVE-2019-0101date:2024-11-21T04:16:13.857

SOURCES RELEASE DATE

db:VULHUBid:VHN-140132date:2019-02-18T00:00:00
db:BIDid:107076date:2019-02-12T00:00:00
db:JVNDBid:JVNDB-2019-001858date:2019-03-27T00:00:00
db:CNNVDid:CNNVD-201902-702date:2019-02-18T00:00:00
db:NVDid:CVE-2019-0101date:2019-02-18T17:29:00.363