ID

VAR-202211-0598


CVE

CVE-2022-26508


TITLE

Intel SDP Tool Authorization problem vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-202211-2626

DESCRIPTION

Improper authentication in the Intel(R) SDP Tool before version 3.0.0 may allow an unauthenticated user to potentially enable information disclosure via network access

Trust: 0.99

sources: NVD: CVE-2022-26508 // VULHUB: VHN-419847

AFFECTED PRODUCTS

vendor:intelmodel:server debug and provisioning toolscope:ltversion:3.0.0

Trust: 1.0

sources: NVD: CVE-2022-26508

CVSS

SEVERITY

CVSSV2

CVSSV3

secure@intel.com: CVE-2022-26508
value: MEDIUM

Trust: 1.0

nvd@nist.gov: CVE-2022-26508
value: HIGH

Trust: 1.0

CNNVD: CNNVD-202211-2626
value: HIGH

Trust: 0.6

secure@intel.com: CVE-2022-26508
baseSeverity: MEDIUM
baseScore: 4.3
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 1.4
version: 3.1

Trust: 1.0

nvd@nist.gov: CVE-2022-26508
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.1

Trust: 1.0

sources: CNNVD: CNNVD-202211-2626 // NVD: CVE-2022-26508 // NVD: CVE-2022-26508

PROBLEMTYPE DATA

problemtype:CWE-287

Trust: 1.1

sources: VULHUB: VHN-419847 // NVD: CVE-2022-26508

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202211-2626

TYPE

authorization issue

Trust: 0.6

sources: CNNVD: CNNVD-202211-2626

PATCH

title:Intel SDP Tool Remediation measures for authorization problem vulnerabilitiesurl:http://123.124.177.30/web/xxk/bdxqById.tag?id=214671

Trust: 0.6

sources: CNNVD: CNNVD-202211-2626

EXTERNAL IDS

db:NVDid:CVE-2022-26508

Trust: 1.7

db:AUSCERTid:ESB-2022.5845

Trust: 0.6

db:CNNVDid:CNNVD-202211-2626

Trust: 0.6

db:VULHUBid:VHN-419847

Trust: 0.1

sources: VULHUB: VHN-419847 // CNNVD: CNNVD-202211-2626 // NVD: CVE-2022-26508

REFERENCES

url:https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00710.html

Trust: 1.7

url:https://www.auscert.org.au/bulletins/esb-2022.5845

Trust: 0.6

url:https://cxsecurity.com/cveshow/cve-2022-26508/

Trust: 0.6

sources: VULHUB: VHN-419847 // CNNVD: CNNVD-202211-2626 // NVD: CVE-2022-26508

SOURCES

db:VULHUBid:VHN-419847
db:CNNVDid:CNNVD-202211-2626
db:NVDid:CVE-2022-26508

LAST UPDATE DATE

2025-02-06T23:11:08.968000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-419847date:2022-11-17T00:00:00
db:CNNVDid:CNNVD-202211-2626date:2022-11-18T00:00:00
db:NVDid:CVE-2022-26508date:2025-02-05T21:15:15.563

SOURCES RELEASE DATE

db:VULHUBid:VHN-419847date:2022-11-11T00:00:00
db:CNNVDid:CNNVD-202211-2626date:2022-11-11T00:00:00
db:NVDid:CVE-2022-26508date:2022-11-11T16:15:12.953