PT-2023-13345 · Intel · Intel Nuc 8 Compute Element+6

Yngweijw

·

Published

2023-05-10

·

Updated

2023-05-22

·

CVE-2022-34147

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Intel(R) NUC 9 Extreme Laptop Kits (affected versions not specified) Intel(R) NUC Performance Kits (affected versions not specified) Intel(R) NUC Performance Mini PC (affected versions not specified) Intel(R) NUC 8 Compute Element (affected versions not specified) Intel(R) NUC Pro Kit (affected versions not specified) Intel(R) NUC Pro Board (affected versions not specified) Intel(R) NUC Compute Element (affected versions not specified)
Description The issue is related to improper input validation in BIOS firmware, which may allow a privileged user to potentially enable escalation of privilege via local access.
Recommendations For Intel(R) NUC 9 Extreme Laptop Kits, update the BIOS firmware to a version that addresses the improper input validation issue. For Intel(R) NUC Performance Kits, update the BIOS firmware to a version that addresses the improper input validation issue. For Intel(R) NUC Performance Mini PC, update the BIOS firmware to a version that addresses the improper input validation issue. For Intel(R) NUC 8 Compute Element, update the BIOS firmware to a version that addresses the improper input validation issue. For Intel(R) NUC Pro Kit, update the BIOS firmware to a version that addresses the improper input validation issue. For Intel(R) NUC Pro Board, update the BIOS firmware to a version that addresses the improper input validation issue. For Intel(R) NUC Compute Element, update the BIOS firmware to a version that addresses the improper input validation issue.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2022-34147

Affected Products

Intel Nuc 8 Compute Element
Intel Nuc 9 Extreme Laptop Kits
Intel Nuc Compute Element
Intel Nuc Performance Kits
Intel Nuc Performance Mini Pc
Intel Nuc Pro Board
Intel Nuc Pro Kit