Home » Database

AVID-2026-R1416

Description

Vulnerability CVE-2024-21799

Details

Path traversal for some Intel(R) Extension for Transformers software before version 1.5 may allow an authenticated user to potentially enable escalation of privilege via local access.

Reason for inclusion in AVID: CVE-2024-21799 describes a path traversal vulnerability in Intel Extension for Transformers software before version 1.5, enabling local privilege escalation. The affected component is a software library used in AI pipelines, thus a software supply chain issue for general-purpose AI systems. It is a security vulnerability with documented references (NVD, Intel advisory).

References

Affected or Relevant Artifacts

  • Developer: n/a
  • Deployer: n/a
  • Artifact Details:
TypeName
SystemIntel(R) Extension for Transformers software

Impact

AVID Taxonomy Categorization

  • Risk domains: Security
  • SEP subcategories: S0100: Software Vulnerability
  • Lifecycle stages: L06: Deployment

CVSS

Version3.1
Vector StringCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Base Score7.1
Base Severity🔴 High
Attack VectorLOCAL
Attack Complexity🟢 Low
Privileges Required🟢 Low
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity Impact🔴 High
Availability Impact🔴 High

CWE

IDDescription
CWE-22Path traversal

Other information

  • Report Type: Advisory
  • Credits:
  • Date Reported: 2024-11-13
  • Version: 0.3.3
  • AVID Entry