LOW · 3.4

CVE-2022-32577

Improper input validation in BIOS Firmware for some Intel(R) NUC Kits before version PY0081 may allow a privileged user to potentially enable information disclosure or denial of service via local acce...

Vulnerability Description

Improper input validation in BIOS Firmware for some Intel(R) NUC Kits before version PY0081 may allow a privileged user to potentially enable information disclosure or denial of service via local access

CVSS Score

3.4

LOW

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
IntelNuc5Cpyh Firmware< py0081
IntelNuc5Cpyh-
IntelNuc5Pgyh Firmware< py0081
IntelNuc5Pgyh-
IntelNuc5Ppyh Firmware< py0081
IntelNuc5Ppyh-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-32577?

CVE-2022-32577 is a vulnerability with a CVSS score of 3.4 (LOW). Improper input validation in BIOS Firmware for some Intel(R) NUC Kits before version PY0081 may allow a privileged user to potentially enable information disclosure or denial of service via local acce...

How severe is CVE-2022-32577?

CVE-2022-32577 has been rated LOW with a CVSS base score of 3.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-32577?

Check the references section above for vendor advisories and patch information. Affected products include: Intel Nuc5Cpyh Firmware, Intel Nuc5Cpyh, Intel Nuc5Pgyh Firmware, Intel Nuc5Pgyh, Intel Nuc5Ppyh Firmware.