Home » Database

AVID-2026-R1452

Description

Vulnerability CVE-2024-29083

Details

Incorrect default permissions in some Intel(R) Distribution for Python software before version 2024.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

Reason for inclusion in AVID: CVE-2024-29083 describes incorrect default permissions in Intel Distribution for Python, enabling local privilege escalation. Intel Distribution for Python is a software runtime used to run AI workloads; thus this is a software supply-chain vulnerability affecting a component commonly used in AI stacks. It is a vulnerability in software (security/safety) with CVE/NVD signals.

References

Affected or Relevant Artifacts

  • Developer: n/a
  • Deployer: n/a
  • Artifact Details:
TypeName
SystemIntel(R) Distribution for Python software

Impact

AVID Taxonomy Categorization

  • Risk domains: Security
  • SEP subcategories: S0100: Software Vulnerability
  • Lifecycle stages: L06: Deployment

CVSS

Version3.1
Vector StringCVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Base Score6.7
Base Severity🟠 Medium
Attack VectorLOCAL
Attack Complexity🔴 High
Privileges Required🟢 Low
User InteractionREQUIRED
ScopeUNCHANGED
Confidentiality Impact🔴 High
Integrity Impact🔴 High
Availability Impact🔴 High

CWE

IDDescription
CWE-276Incorrect default permissions

Other information

  • Report Type: Advisory
  • Credits:
  • Date Reported: 2024-11-13
  • Version: 0.3.3
  • AVID Entry