Lucene search

K
cve[email protected]CVE-2022-21933
HistoryJan 21, 2022 - 9:15 a.m.

CVE-2022-21933

2022-01-2109:15:06
CWE-787
CWE-20
web.nvd.nist.gov
36
cve-2022-21933
asus
vivomini
mini pc
input validation
vulnerability
local attacker
system privilege
smi
memory modification
arbitrary code execution
system control
service disruption

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.0004 Low

EPSS

Percentile

5.1%

ASUS VivoMini/Mini PC device has an improper input validation vulnerability. A local attacker with system privilege can use system management interrupt (SMI) to modify memory, resulting in arbitrary code execution for controlling the system or disrupting service.

Affected configurations

NVD
Node
asusvc65-c1_firmwareRange<1302
AND
asusvc65-c1Match-
Node
asuspb60v_firmwareRange<1302
AND
asuspb60vMatch-
Node
asuspb60g_firmwareRange<1302
AND
asuspb60gMatch-
Node
asuspb60s_firmwareRange<1302
AND
asuspb60sMatch-
Node
asuspa90_firmwareRange<1401
AND
asuspa90Match-
Node
asuspb50_firmwareRange<902
AND
asuspb50Match-
Node
asuspb60_firmwareRange<1502
AND
asuspb60Match-
Node
asuspb61v_firmwareRange<601
AND
asuspb61vMatch-
Node
asusts10_firmwareRange<609
AND
asusts10Match-
Node
asuspn40_firmwareRange<2201
AND
asuspn40Match-
Node
asuspn60_firmwareRange<808
AND
asuspn60Match-
Node
asuspn30_firmwareRange<320
AND
asuspn30Match-
Node
asusun65u_firmwareRange<618
AND
asusun65uMatch-

CNA Affected

[
  {
    "product": "VC65-C1",
    "vendor": "ASUS",
    "versions": [
      {
        "lessThan": "1302",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "PB60V",
    "vendor": "ASUS",
    "versions": [
      {
        "lessThan": "1302",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "PB60G",
    "vendor": "ASUS",
    "versions": [
      {
        "lessThan": "1302",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "PB60S",
    "vendor": "ASUS",
    "versions": [
      {
        "lessThan": "1302",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "PA90",
    "vendor": "ASUS",
    "versions": [
      {
        "lessThan": "1401",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "PB50",
    "vendor": "ASUS",
    "versions": [
      {
        "lessThan": "902",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "PB60",
    "vendor": "ASUS",
    "versions": [
      {
        "lessThan": "1502",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "PB61V",
    "vendor": "ASUS",
    "versions": [
      {
        "lessThan": "601",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "TS10",
    "vendor": "ASUS",
    "versions": [
      {
        "lessThan": "609",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "PN40",
    "vendor": "ASUS",
    "versions": [
      {
        "lessThan": "2201",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "PN60",
    "vendor": "ASUS",
    "versions": [
      {
        "lessThan": "808",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "PN30",
    "vendor": "ASUS",
    "versions": [
      {
        "lessThan": "320",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "UN65U",
    "vendor": "ASUS",
    "versions": [
      {
        "lessThan": "618",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.0004 Low

EPSS

Percentile

5.1%

Related for CVE-2022-21933