HIGH · 8.2

CVE-2018-12176

Improper input validation in firmware for Intel NUC Kits may allow a privileged user to potentially execute arbitrary code resulting in information disclosure, escalation of privilege and/or denial of...

Vulnerability Description

Improper input validation in firmware for Intel NUC Kits may allow a privileged user to potentially execute arbitrary code resulting in information disclosure, escalation of privilege and/or denial of service via local access.

CVSS Score

8.2

HIGH

CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
IntelNuc Kit Firmware-
IntelNuc Kit D33217Gke-
IntelNuc Kit D53427Rke-
IntelNuc Kit D54250Wyb-
IntelNuc Kit De3815Tybe-
IntelNuc Kit Dn2820Fykh-
IntelNuc Kit Nuc5Cpyh-
IntelNuc Kit Nuc5I3Myhe-
IntelNuc Kit Nuc5I5Myhe-
IntelNuc Kit Nuc5I7Ryh-
IntelNuc Kit Nuc5Pgyh-
IntelNuc Kit Nuc6Cays-
IntelNuc Kit Nuc6I5Syh-
IntelNuc Kit Nuc6I7Kyk-
IntelNuc Kit Nuc7Cjyh-
IntelNuc Kit Nuc7I3Dnhe-
IntelNuc Kit Nuc7I5Dnke-
IntelNuc Kit Nuc7I7Bnh-
IntelNuc Kit Nuc7I7Dnke-
IntelNuc Kit Nuc8I7Hnk-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-12176?

CVE-2018-12176 is a vulnerability with a CVSS score of 8.2 (HIGH). Improper input validation in firmware for Intel NUC Kits may allow a privileged user to potentially execute arbitrary code resulting in information disclosure, escalation of privilege and/or denial of...

How severe is CVE-2018-12176?

CVE-2018-12176 has been rated HIGH with a CVSS base score of 8.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-12176?

Check the references section above for vendor advisories and patch information. Affected products include: Intel Nuc Kit Firmware, Intel Nuc Kit D33217Gke, Intel Nuc Kit D53427Rke, Intel Nuc Kit D54250Wyb, Intel Nuc Kit De3815Tybe.