intel Vulnerabilities and Affected Products
Vulnerabilities associated with neural_compressor_software.
Products
Clear product- RAID Web Console 3 (RWC3)19 vulnerabilities
- Intel(R) Graphics Drivers16 vulnerabilities
- power_gadget_software11 vulnerabilities
- VirusScan Enterprise Linux (VSEL)10 vulnerabilities
- ethernet_complete_driver_pack7 vulnerabilities
- graphics_performance_analyzer7 vulnerabilities
- raid_web_console_36 vulnerabilities
- media_sdk5 vulnerabilities
- neural_compressor_software5 vulnerabilities
- oneapi_base_toolkit5 vulnerabilities
- 4th_generation_intel_xeon_processor_scalable_family4 vulnerabilities
- 5th_generation_intel_xeon_processor_scalable_family4 vulnerabilities
- advisor4 vulnerabilities
- ethernet_controller_i225_manageability_firmware4 vulnerabilities
- server_system_d50tnp2mhsvac_firmware4 vulnerabilities
- vroc_software4 vulnerabilities
- agilex_7_fpga_f-series_019_firmware3 vulnerabilities
- aptio_v_uefi_firmware_integrator_tools3 vulnerabilities
- bios3 vulnerabilities
- comet_lake3 vulnerabilities
- context_sensing_technology3 vulnerabilities
- driver\&support_assistant3 vulnerabilities
- dsa_software3 vulnerabilities
- ethernet_adapter3 vulnerabilities
- ethernet_adapter_complete_driver_pack3 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-39766HIGH | Improper neutralization of special elements used in SQL command in some Intel(R) Neural Compressor software before version v3.0 may allow an authenticated user to potentially enable escalation of privilege via local access. CWE-1336Nov 13, 2024 | CVSS7.3v4.0 | EPSS0.227% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-28028HIGH | Improper input validation in some Intel(R) Neural Compressor software before version v3.0 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access. CWE-20Nov 13, 2024 | CVSS7.7v4.0 | EPSS0.3% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-39368HIGH | Improper neutralization of special elements used in an SQL command ('SQL Injection') in some Intel(R) Neural Compressor software before version v3.0 may allow an authenticated user to potentially enable escalation of privilege via adjacent access. CWE-89Nov 13, 2024 | CVSS8.6v4.0 | EPSS0.33% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-21792MEDIUM | Time-of-check Time-of-use race condition in Intel(R) Neural Compressor software before version 2.5.0 may allow an authenticated user to potentially enable information disclosure via local access. CWE-367May 16, 2024 | CVSS4.7v3.1 | EPSS0.136% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-22476CRITICAL | Intel Neural Compressor <2.5.0 - SQL InjectionImproper input validation in some Intel(R) Neural Compressor software before version 2.5.0 may allow an unauthenticated user to potentially enable escalation of privilege via remote access. | CVSS10.0v3.1 | EPSS35.7% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |