Attacker Value
Unknown
0
CVE-2023-22327
0
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
CVE-2023-22327
(Last updated November 28, 2023) ▾
MITRE ATT&CK
Log in to add MITRE ATT&CK tag
Add MITRE ATT&CK tactics and techniques that apply to this CVE.
MITRE ATT&CK
Select the MITRE ATT&CK Tactics that apply to this CVE
Collection
Select any Techniques used:
Command and Control
Select any Techniques used:
Credential Access
Select any Techniques used:
Defense Evasion
Select any Techniques used:
Discovery
Select any Techniques used:
Execution
Select any Techniques used:
Exfiltration
Select any Techniques used:
Impact
Select any Techniques used:
Initial Access
Select any Techniques used:
Lateral Movement
Select any Techniques used:
Persistence
Select any Techniques used:
Privilege Escalation
Select any Techniques used:
Topic Tags
Select the tags that apply to this CVE (Assessment added tags are disabled and cannot be removed)
What makes this of high-value to an attacker?
What makes this of low-value to an attacker?
Description
Out-of-bounds write in firmware for some Intel® FPGA products before version 2.8.1 may allow a privileged user to potentially enable information disclosure via local access.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
Data provided by the National Vulnerability Database (NVD)
Base Score:
4.4 Medium
Impact Score:
3.6
Exploitability Score:
0.8
Attack Vector (AV):
Local
Attack Complexity (AC):
Low
Privileges Required (PR):
High
User Interaction (UI):
None
Scope (S):
Unchanged
Confidentiality (C):
High
Integrity (I):
None
Availability (A):
None
General Information
Offensive Application
Unknown
Utility Class
Unknown
Ports
Unknown
OS
Unknown
Vulnerable Versions
Intel(R) FPGA products before version 2.8.1
Prerequisites
Unknown
Discovered By
Unknown
PoC Author
Unknown
Metasploit Module
Unknown
Reporter
Unknown
Vendors
Products
- agilex 7 fpga f series 006 firmware
- agilex 7 fpga f series 008 firmware
- agilex 7 fpga f series 012 firmware
- agilex 7 fpga f series 014 firmware
- agilex 7 fpga f series 019 firmware
- agilex 7 fpga f series 022 firmware
- agilex 7 fpga f series 023 firmware
- agilex 7 fpga f series 027 firmware
- agilex 7 fpga i series 019 firmware
- agilex 7 fpga i series 022 firmware
- agilex 7 fpga i series 023 firmware
- agilex 7 fpga i series 027 firmware
- agilex 7 fpga i series 035 firmware
- agilex 7 fpga i series 040 firmware
- agilex 7 fpga i series 041 firmware
- agilex 7 fpga m series 039 firmware
- stratix 10 dx 1100 fpga firmware
- stratix 10 dx 2100 fpga firmware
- stratix 10 dx 2800 fpga firmware
- stratix 10 gx 10m fpga firmware
- stratix 10 gx 1100 fpga firmware
- stratix 10 gx 1650 fpga firmware
- stratix 10 gx 1660 fpga firmware
- stratix 10 gx 2100 fpga firmware
- stratix 10 gx 2110 fpga firmware
- stratix 10 gx 2500 fpga firmware
- stratix 10 gx 2800 fpga firmware
- stratix 10 gx 400 fpga firmware
- stratix 10 gx 650 fpga firmware
- stratix 10 gx 850 fpga firmware
- stratix 10 mx 1650 fpga firmware
- stratix 10 mx 2100 fpga firmware
- stratix 10 nx 2100 fpga firmware
- stratix 10 sx 1100 fpga firmware
- stratix 10 sx 1650 fpga firmware
- stratix 10 sx 2100 fpga firmware
- stratix 10 sx 2500 fpga firmware
- stratix 10 sx 2800 fpga firmware
- stratix 10 sx 400 fpga firmware
- stratix 10 sx 650 fpga firmware
- stratix 10 sx 850 fpga firmware
- stratix 10 tx 1100 fpga firmware
- stratix 10 tx 1650 fpga firmware
- stratix 10 tx 2100 fpga firmware
- stratix 10 tx 2500 fpga firmware
- stratix 10 tx 2800 fpga firmware
- stratix 10 tx 400 fpga firmware
- stratix 10 tx 850 fpga firmware
References
Additional Info
Authenticated
Unknown
Exploitable
Unknown
Reliability
Unknown
Stability
Unknown
Available Mitigations
Unknown
Shelf Life
Unknown
Userbase/Installbase
Unknown
Patch Effectiveness
Unknown
Rapid7
Technical Analysis
Report as Emergent Threat Response
Report as Zero-day Exploit
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: