Lucene search

K
cvelistIntelCVELIST:CVE-2022-34152
HistoryNov 11, 2022 - 3:48 p.m.

CVE-2022-34152

2022-11-1115:48:51
intel
www.cve.org
1
cve-2022-34152
input validation
bios firmware
intel nuc
escalation of privilege
local access

CVSS3

7.7

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H

EPSS

0

Percentile

12.6%

Improper input validation in BIOS firmware for some Intelยฎ NUC Boards, Intelยฎ NUC Kits before version TY0070 may allow a privileged user to potentially enable escalation of privilege via local access.

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "Intel(R) NUC Boards, Intel(R) NUC Kits",
    "versions": [
      {
        "version": "before version TY0070",
        "status": "affected"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

CVSS3

7.7

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H

EPSS

0

Percentile

12.6%

Related for CVELIST:CVE-2022-34152