CVSS3
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
CVSS4
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/SC:H/VI:H/SI:H/VA:H/SA:H
EPSS
Percentile
9.6%
SSVC
Exploitation
none
Automatable
no
Technical Impact
total
Improper access control in UEFI firmware for some Intel® Processors may allow a privileged user to potentially enable escalation of privilege via local access.
[
{
"cpes": [
"cpe:2.3:o:intel:atom_c2308_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:intel:atom_c2316_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:intel:atom_c2338_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:intel:atom_c2350_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:intel:atom_c2358_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:intel:atom_c2508_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:intel:atom_c2516_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:intel:atom_c2518_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:intel:atom_c2530_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:intel:atom_c2538_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:intel:atom_c2550_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:intel:atom_c2558_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:intel:atom_c2718_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:intel:atom_c2730_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:intel:atom_c2738_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:intel:atom_c2750_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:intel:atom_c2758_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:intel:atom_c3000_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:intel:atom_c3308_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:intel:atom_c3336_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:intel:atom_c3338_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:intel:atom_c3338r_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:intel:atom_c3436l_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:intel:atom_c3508_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:intel:atom_c3538_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:intel:atom_c3558_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:intel:atom_c3558rc_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:intel:atom_c3558r_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:intel:atom_c3708_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:intel:atom_c3750_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:intel:atom_c3758_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:intel:atom_c3758r_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:intel:atom_c3808_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:intel:atom_c3830_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:intel:atom_c3850_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:intel:atom_c3858_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:intel:atom_c3950_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:intel:atom_c3955_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:intel:atom_c3958_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:intel:atom_c5115_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:intel:atom_c5125_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:intel:atom_c5310_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:intel:atom_c5315_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:intel:atom_c5320_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:intel:atom_c5325_firmware:-:*:*:*:*:*:*:*"
],
"vendor": "intel",
"product": "atom_c5325_firmware",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "*",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
}
]
CVSS3
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
CVSS4
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/SC:H/VI:H/SI:H/VA:H/SA:H
EPSS
Percentile
9.6%
SSVC
Exploitation
none
Automatable
no
Technical Impact
total