Record summary

CVE-2024-22476 has a selected CVSS score of 10.0 (critical); EIP currently links 1 Nuclei template.

Description

Improper input validation in some Intel(R) Neural Compressor software before version 2.5.0 may allow an unauthenticated user to potentially enable escalation of privilege via remote access.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated May 20, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unknown

CVE List- to < 2.5.0affected

Intel(R) Neural Compressor software

Default status: unaffected

CVE Listbefore version 2.5.0affected

Nuclei templates

1
ProjectDiscoveryCRITICALIntel Neural Compressor <2.5.0 - SQL InjectionCVSS 10

Improper input validation in some Intel(R) Neural Compressor software before version 2.5.0 may allow an unauthenticated user to potentially enable escalation of privilege via remote access.

Impact

Unauthenticated attackers can escalate privileges or perform malicious actions through improper input validation in Intel Neural Compressor.

Remediation

Update Intel Neural Compressor to version 2.5.0 or later.

WeaknessesCWE-20
Authorsritikchaddha, daffainfo
Template tagscvecve2024intelneural-compressorsqliintrusivevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Source: ProjectDiscovery

References

2