Lucene search

K
cveIntelCVE-2022-34657
HistoryAug 11, 2023 - 3:15 a.m.

CVE-2022-34657

2023-08-1103:15:12
CWE-20
intel
web.nvd.nist.gov
17
cve-2022-34657
intel pcsd bios
input validation
privilege escalation
firmware vulnerability

CVSS3

6

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

AI Score

4.3

Confidence

High

EPSS

0

Percentile

9.0%

Improper input validation in firmware for some Intelยฎ PCSD BIOS before version 02.01.0013 may allow a privileged user to potentially enable information disclosure via local access.

Affected configurations

Nvd
Vulners
Node
intelr1208wfqysrMatch-
OR
intelr1208wftysMatch-
OR
intelr1208wftysrMatch-
OR
intelr1304wf0ysMatch-
OR
intelr1304wf0ysrMatch-
OR
intelr1304wftysMatch-
OR
intelr1304wftysrMatch-
OR
intelr2208wf0zsMatch-
OR
intelr2208wf0zsrMatch-
OR
intelr2208wfqzsMatch-
OR
intelr2208wfqzsrMatch-
OR
intelr2208wftzsMatch-
OR
intelr2208wftzsrMatch-
OR
intelr2224wfqzsMatch-
OR
intelr2224wftzsMatch-
OR
intelr2224wftzsrMatch-
OR
intelr2308wftzsMatch-
OR
intelr2308wftzsrMatch-
OR
intelr2312wf0npMatch-
OR
intelr2312wf0nprMatch-
OR
intelr2312wfqzsMatch-
OR
intelr2312wftzsMatch-
OR
intelr2312wftzsrMatch-
OR
intels2600wf0Match-
OR
intels2600wf0rMatch-
OR
intels2600wfqMatch-
OR
intels2600wfqrMatch-
OR
intels2600wftMatch-
OR
intels2600wftfMatch-
OR
intels2600wftrMatch-
AND
intelpcsd_biosRange<02.01.0013
VendorProductVersionCPE
intelr1208wfqysr-cpe:2.3:h:intel:r1208wfqysr:-:*:*:*:*:*:*:*
intelr1208wftys-cpe:2.3:h:intel:r1208wftys:-:*:*:*:*:*:*:*
intelr1208wftysr-cpe:2.3:h:intel:r1208wftysr:-:*:*:*:*:*:*:*
intelr1304wf0ys-cpe:2.3:h:intel:r1304wf0ys:-:*:*:*:*:*:*:*
intelr1304wf0ysr-cpe:2.3:h:intel:r1304wf0ysr:-:*:*:*:*:*:*:*
intelr1304wftys-cpe:2.3:h:intel:r1304wftys:-:*:*:*:*:*:*:*
intelr1304wftysr-cpe:2.3:h:intel:r1304wftysr:-:*:*:*:*:*:*:*
intelr2208wf0zs-cpe:2.3:h:intel:r2208wf0zs:-:*:*:*:*:*:*:*
intelr2208wf0zsr-cpe:2.3:h:intel:r2208wf0zsr:-:*:*:*:*:*:*:*
intelr2208wfqzs-cpe:2.3:h:intel:r2208wfqzs:-:*:*:*:*:*:*:*
Rows per page:
1-10 of 311

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "Intel(R) PCSD BIOS",
    "versions": [
      {
        "version": "before version 02.01.0013",
        "status": "affected"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

CVSS3

6

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

AI Score

4.3

Confidence

High

EPSS

0

Percentile

9.0%

Related for CVE-2022-34657