CVE-2023-32277

MEDIUM

Intel QAT <2.0.5 - Info Disclosure

Title source: llm
STIX 2.1

Description

Untrusted Pointer Dereference in I/O subsystem for some Intel(R) QAT software before version 2.0.5 may allow authenticated user to potentially enable information disclosure via local operating system access.

Scores

CVSS v3 6.1
EPSS 0.0009
EPSS Percentile 25.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-822
Status published
Products (1)
n/a/Intel(R) QAT software before version 2.0.5
Published Feb 12, 2025
Tracked Since Feb 18, 2026