HIGH · 7.9

CVE-2022-37336

Improper input validation in BIOS firmware for some Intel(R) NUC may allow a privileged user to potentially enable escalation of privilege via local access.

Vulnerability Description

Improper input validation in BIOS firmware for some Intel(R) NUC may allow a privileged user to potentially enable escalation of privilege via local access.

CVSS Score

7.9

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
CHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
IntelNuc 10 Performance Kit Nuc10I7Fnhn Firmware-
IntelNuc 10 Performance Kit Nuc10I7Fnhn-
IntelNuc 10 Performance Kit Nuc10I5Fnkn Firmware-
IntelNuc 10 Performance Kit Nuc10I5Fnkn-
IntelNuc 10 Performance Kit Nuc10I5Fnhn Firmware-
IntelNuc 10 Performance Kit Nuc10I5Fnhn-
IntelNuc 10 Performance Kit Nuc10I7Fnkn Firmware-
IntelNuc 10 Performance Kit Nuc10I7Fnkn-
IntelNuc 10 Performance Kit Nuc10I3Fnhn Firmware-
IntelNuc 10 Performance Kit Nuc10I3Fnhn-
IntelNuc 10 Performance Kit Nuc10I3Fnkn Firmware-
IntelNuc 10 Performance Kit Nuc10I3Fnkn-
IntelNuc 10 Performance Mini Pc Nuc10I5Fnhja Firmware-
IntelNuc 10 Performance Mini Pc Nuc10I5Fnhja-
IntelNuc 10 Performance Kit Nuc10I3Fnhf Firmware-
IntelNuc 10 Performance Kit Nuc10I3Fnhf-
IntelNuc 10 Performance Mini Pc Nuc10I7Fnkpa Firmware-
IntelNuc 10 Performance Mini Pc Nuc10I7Fnkpa-
IntelNuc 10 Performance Mini Pc Nuc10I5Fnhca Firmware-
IntelNuc 10 Performance Mini Pc Nuc10I5Fnhca-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-37336?

CVE-2022-37336 is a vulnerability with a CVSS score of 7.9 (HIGH). Improper input validation in BIOS firmware for some Intel(R) NUC may allow a privileged user to potentially enable escalation of privilege via local access.

How severe is CVE-2022-37336?

CVE-2022-37336 has been rated HIGH with a CVSS base score of 7.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-37336?

Check the references section above for vendor advisories and patch information. Affected products include: Intel Nuc 10 Performance Kit Nuc10I7Fnhn Firmware, Intel Nuc 10 Performance Kit Nuc10I7Fnhn, Intel Nuc 10 Performance Kit Nuc10I5Fnkn Firmware, Intel Nuc 10 Performance Kit Nuc10I5Fnkn, Intel Nuc 10 Performance Kit Nuc10I5Fnhn Firmware.