CVE-2023-28396
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Feb 14, 2024
CWE ID 284
Summary
CVE-2023-28396 is a vulnerability affecting some versions of Intel(R) Thunderbolt(TM) Controllers prior to 41. This issue involves improper access control in the firmware, enabling a privileged user to trigger a denial-of-service condition through local access. Successful exploitation could lead to service interruption, potentially causing inconvenience or downtime in affected systems. Intel urges users to update their controllers to the latest firmware version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share