CVE-2023-23908

Updated: 2026-02-27 01:12:00.613397

Description:

Improper access control in some 3rd Generation Intel(R) Xeon(R) Scalable processors may allow a privileged user to potentially enable information disclosure via local access.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x MEDIUM 4.4

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU microcode_ctl 20220809 4.4 MEDIUM Ignored 2023-12-01 03:18:44 This vulnerability requires local, already high-privileged access and only enables information discl...
CentOS 6 ELS microcode_ctl 1.17-33.29 4.4 MEDIUM Ignored 2023-12-01 03:18:45 Ignored due to low severity
CentOS 7 ELS microcode_ctl 2.1 4.4 MEDIUM Released CLSA-2023:1701444720 2023-12-01 13:09:22
CentOS 8.4 ELS microcode_ctl 20210216-1 4.4 MEDIUM Ignored 2023-12-01 03:18:45 Ignored due to low severity
CentOS 8.5 ELS microcode_ctl 20210608-1 4.4 MEDIUM Ignored 2023-12-01 03:18:45 Ignored due to low severity
CloudLinux 6 ELS microcode_ctl 1.17-33.29 4.4 MEDIUM Ignored 2023-12-01 03:18:45 Ignored due to low severity
Oracle Linux 6 ELS microcode_ctl 1.17-33.29 4.4 MEDIUM Ignored 2023-12-01 03:18:45 Ignored due to low severity
Ubuntu 16.04 ELS intel-microcode 3.20201110.0 4.4 MEDIUM Released CLSA-2023:1693419056 2023-08-30 17:06:04
Ubuntu 18.04 ELS intel-microcode 3.20220809.0 4.4 MEDIUM Released CLSA-2023:1693419791 2023-08-30 17:06:05