Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-0135


Improper permissions in the installer for Intel(R) Accelerated Storage Manager in Intel(R) RSTe before version 5.5.0.2015 may allow an authenticated user to potentially enable escalation of privilege via local access. L-SA-00206


Published

2019-03-14T20:29:01.600

Last Modified

2024-11-21T04:16:18.483

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

3.9

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-264

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application intel rapid_storage_technology_enterprise < 5.5.0.2015 Yes
Operating System lenovo thinkstation_p520_firmware - Yes
Hardware lenovo thinkstation_p520 - No
Operating System lenovo thinkstation_p520c_firmware - Yes
Hardware lenovo thinkstation_p520c - No
Operating System lenovo thinkstation_p720_firmware - Yes
Hardware lenovo thinkstation_p720 - No
Operating System lenovo thinkstation_p920_firmware - Yes
Hardware lenovo thinkstation_p920 - No

References