CVE-2023-28938 is an uncontrolled resource consumption vulnerability affecting Intel SSD Tools software prior to version mdadm-4.2-rc2. A privileged local attacker could exploit this to cause a denial of service. With a CVSS score of 4.4 (Medium), this vulnerability requires high privileges and local access, impacting availability but not confidentiality or integrity. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.2CPE matchmatch criteria | cpe:2.3:a:mdadm_project:mdadm:*:*:*:*:*:*:*:* | ||
4.2CPE matchmatch criteria | cpe:2.3:a:mdadm_project:mdadm:4.2:rc1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2023-28938
Jun 11, 2024mdadm: Uncontrolled resource consumption
Aug 11, 2023Uncontrolled resource consumption in some Intel(R) SSD Tools software before version mdadm-4.2-rc2 may allow a priviledged user to potentially enable denial of service via local access.
Aug 8, 2023