MEDIUM · 6.7

CVE-2022-21933

ASUS VivoMini/Mini PC device has an improper input validation vulnerability. A local attacker with system privilege can use system management interrupt (SMI) to modify memory, resulting in arbitrary c...

Vulnerability Description

ASUS VivoMini/Mini PC device has an improper input validation vulnerability. A local attacker with system privilege can use system management interrupt (SMI) to modify memory, resulting in arbitrary code execution for controlling the system or disrupting service.

CVSS Score

6.7

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
AsusVc65-C1 Firmware< 1302
AsusVc65-C1-
AsusPb60V Firmware< 1302
AsusPb60V-
AsusPb60G Firmware< 1302
AsusPb60G-
AsusPb60S Firmware< 1302
AsusPb60S-
AsusPa90 Firmware< 1401
AsusPa90-
AsusPb50 Firmware< 902
AsusPb50-
AsusPb60 Firmware< 1502
AsusPb60-
AsusPb61V Firmware< 601
AsusPb61V-
AsusTs10 Firmware< 609
AsusTs10-
AsusPn40 Firmware< 2201
AsusPn40-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-21933?

CVE-2022-21933 is a vulnerability with a CVSS score of 6.7 (MEDIUM). ASUS VivoMini/Mini PC device has an improper input validation vulnerability. A local attacker with system privilege can use system management interrupt (SMI) to modify memory, resulting in arbitrary c...

How severe is CVE-2022-21933?

CVE-2022-21933 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-21933?

Check the references section above for vendor advisories and patch information. Affected products include: Asus Vc65-C1 Firmware, Asus Vc65-C1, Asus Pb60V Firmware, Asus Pb60V, Asus Pb60G Firmware.