MEDIUM · 6.0

CVE-2023-22444

Improper initialization in some Intel(R) NUC 13 Extreme Compute Element, Intel(R) NUC 13 Extreme Kit, Intel(R) NUC 11 Performance Kit, Intel(R) NUC 11 Performance Mini PC, Intel(R) NUC Compute Element...

Vulnerability Description

Improper initialization in some Intel(R) NUC 13 Extreme Compute Element, Intel(R) NUC 13 Extreme Kit, Intel(R) NUC 11 Performance Kit, Intel(R) NUC 11 Performance Mini PC, Intel(R) NUC Compute Element, Intel(R) NUC Laptop Kit, Intel(R) NUC Pro Kit, Intel(R) NUC Pro Board and Intel(R) NUC Pro Mini PC BIOS firmware may allow a privileged user to potentially enable information disclosure via local access.

CVSS Score

6.0

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
IntelNuc 13 Extreme Compute Element Nuc13Sbbi7F Firmware-
IntelNuc 13 Extreme Compute Element Nuc13Sbbi7F-
IntelNuc 13 Extreme Compute Element Nuc13Sbbi5F Firmware-
IntelNuc 13 Extreme Compute Element Nuc13Sbbi5F-
IntelNuc 13 Extreme Compute Element Nuc13Sbbi9F Firmware-
IntelNuc 13 Extreme Compute Element Nuc13Sbbi9F-
IntelNuc 13 Extreme Kit Nuc13Rngi7 Firmware-
IntelNuc 13 Extreme Kit Nuc13Rngi7-
IntelNuc 13 Extreme Kit Nuc13Rngi9 Firmware-
IntelNuc 13 Extreme Kit Nuc13Rngi9-
IntelNuc 13 Extreme Kit Nuc13Rngi5 Firmware-
IntelNuc 13 Extreme Kit Nuc13Rngi5-
IntelNuc 13 Extreme Compute Element Nuc13Sbbi7 Firmware-
IntelNuc 13 Extreme Compute Element Nuc13Sbbi7-
IntelNuc 13 Extreme Compute Element Nuc13Sbbi5 Firmware-
IntelNuc 13 Extreme Compute Element Nuc13Sbbi5-
IntelNuc 13 Extreme Compute Element Nuc13Sbbi9 Firmware-
IntelNuc 13 Extreme Compute Element Nuc13Sbbi9-
IntelNuc 11 Performance Kit Nuc11Pahi70Z Firmware-
IntelNuc 11 Performance Kit Nuc11Pahi70Z-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-22444?

CVE-2023-22444 is a vulnerability with a CVSS score of 6.0 (MEDIUM). Improper initialization in some Intel(R) NUC 13 Extreme Compute Element, Intel(R) NUC 13 Extreme Kit, Intel(R) NUC 11 Performance Kit, Intel(R) NUC 11 Performance Mini PC, Intel(R) NUC Compute Element...

How severe is CVE-2023-22444?

CVE-2023-22444 has been rated MEDIUM with a CVSS base score of 6.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-22444?

Check the references section above for vendor advisories and patch information. Affected products include: Intel Nuc 13 Extreme Compute Element Nuc13Sbbi7F Firmware, Intel Nuc 13 Extreme Compute Element Nuc13Sbbi7F, Intel Nuc 13 Extreme Compute Element Nuc13Sbbi5F Firmware, Intel Nuc 13 Extreme Compute Element Nuc13Sbbi5F, Intel Nuc 13 Extreme Compute Element Nuc13Sbbi9F Firmware.