Lucene search

K
cveIntelCVE-2023-28738
HistoryJan 19, 2024 - 8:15 p.m.

CVE-2023-28738

2024-01-1920:15:09
CWE-20
intel
web.nvd.nist.gov
7
cve-2023-28738
intel
nuc
bios firmware
input validation
privilege escalation
local access
security vulnerability
nvd

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.6

Confidence

High

EPSS

0

Percentile

9.0%

Improper input validation for some Intel NUC BIOS firmware before version JY0070 may allow a privileged user to potentially enable escalation of privilege via local access.

Affected configurations

Nvd
Node
intelnuc_7_essential_nuc7cjysamnMatch-
AND
intelnuc_7_essential_nuc7cjysamn_firmwareMatchjyglkcpx.0071
Node
intelnuc_kit_nuc7cjyhnMatch-
AND
intelnuc_kit_nuc7cjyhn_firmwareMatchjyglkcpx.0071
Node
intelnuc_kit_nuc7pjyhnMatch-
AND
intelnuc_kit_nuc7pjyhn_firmwareMatchjyglkcpx.0071
Node
intelnuc_kit_nuc7pjyhMatch-
AND
intelnuc_kit_nuc7pjyh_firmwareMatchjyglkcpx.0071
Node
intelnuc_kit_nuc7cjysalMatch-
AND
intelnuc_kit_nuc7cjysal_firmwareMatchjyglkcpx.0071
Node
intelnuc_kit_nuc7cjyhMatch-
AND
intelnuc_kit_nuc7cjyh_firmwareMatchjyglkcpx.0071
VendorProductVersionCPE
intelnuc_7_essential_nuc7cjysamn-cpe:2.3:h:intel:nuc_7_essential_nuc7cjysamn:-:*:*:*:*:*:*:*
intelnuc_7_essential_nuc7cjysamn_firmwarejyglkcpx.0071cpe:2.3:o:intel:nuc_7_essential_nuc7cjysamn_firmware:jyglkcpx.0071:*:*:*:*:*:*:*
intelnuc_kit_nuc7cjyhn-cpe:2.3:h:intel:nuc_kit_nuc7cjyhn:-:*:*:*:*:*:*:*
intelnuc_kit_nuc7cjyhn_firmwarejyglkcpx.0071cpe:2.3:o:intel:nuc_kit_nuc7cjyhn_firmware:jyglkcpx.0071:*:*:*:*:*:*:*
intelnuc_kit_nuc7pjyhn-cpe:2.3:h:intel:nuc_kit_nuc7pjyhn:-:*:*:*:*:*:*:*
intelnuc_kit_nuc7pjyhn_firmwarejyglkcpx.0071cpe:2.3:o:intel:nuc_kit_nuc7pjyhn_firmware:jyglkcpx.0071:*:*:*:*:*:*:*
intelnuc_kit_nuc7pjyh-cpe:2.3:h:intel:nuc_kit_nuc7pjyh:-:*:*:*:*:*:*:*
intelnuc_kit_nuc7pjyh_firmwarejyglkcpx.0071cpe:2.3:o:intel:nuc_kit_nuc7pjyh_firmware:jyglkcpx.0071:*:*:*:*:*:*:*
intelnuc_kit_nuc7cjysal-cpe:2.3:h:intel:nuc_kit_nuc7cjysal:-:*:*:*:*:*:*:*
intelnuc_kit_nuc7cjysal_firmwarejyglkcpx.0071cpe:2.3:o:intel:nuc_kit_nuc7cjysal_firmware:jyglkcpx.0071:*:*:*:*:*:*:*
Rows per page:
1-10 of 121

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "Intel NUC BIOS firmware",
    "versions": [
      {
        "version": "before version JY0070",
        "status": "affected"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.6

Confidence

High

EPSS

0

Percentile

9.0%

Related for CVE-2023-28738