Vulnerability Description
Improper input validation in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Intel | Nuc 13 Extreme Compute Element Nuc13Sbbi5 Firmware | - |
| Intel | Nuc 13 Extreme Compute Element Nuc13Sbbi5 | - |
| Intel | Nuc 13 Extreme Compute Element Nuc13Sbbi5F Firmware | - |
| Intel | Nuc 13 Extreme Compute Element Nuc13Sbbi5F | - |
| Intel | Nuc 13 Extreme Compute Element Nuc13Sbbi7 Firmware | - |
| Intel | Nuc 13 Extreme Compute Element Nuc13Sbbi7 | - |
| Intel | Nuc 13 Extreme Compute Element Nuc13Sbbi7F Firmware | - |
| Intel | Nuc 13 Extreme Compute Element Nuc13Sbbi7F | - |
| Intel | Nuc 13 Extreme Compute Element Nuc13Sbbi9 Firmware | - |
| Intel | Nuc 13 Extreme Compute Element Nuc13Sbbi9 | - |
| Intel | Nuc 13 Extreme Compute Element Nuc13Sbbi9F Firmware | - |
| Intel | Nuc 13 Extreme Compute Element Nuc13Sbbi9F | - |
| Intel | Nuc 13 Extreme Kit Nuc13Rngi5 Firmware | - |
| Intel | Nuc 13 Extreme Kit Nuc13Rngi5 | - |
| Intel | Nuc 13 Extreme Kit Nuc13Rngi7 Firmware | - |
| Intel | Nuc 13 Extreme Kit Nuc13Rngi7 | - |
| Intel | Nuc 13 Extreme Kit Nuc13Rngi9 Firmware | - |
| Intel | Nuc 13 Extreme Kit Nuc13Rngi9 | - |
| Intel | Nuc 11 Performance Kit Nuc11Pahi3 Firmware | - |
| Intel | Nuc 11 Performance Kit Nuc11Pahi3 | - |
Related Weaknesses (CWE)
References
- http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00917.hPatchVendor Advisory
- http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00917.hPatchVendor Advisory
FAQ
What is CVE-2023-22449?
CVE-2023-22449 is a vulnerability with a CVSS score of 7.5 (HIGH). Improper input validation in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.
How severe is CVE-2023-22449?
CVE-2023-22449 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-22449?
Check the references section above for vendor advisories and patch information. Affected products include: Intel Nuc 13 Extreme Compute Element Nuc13Sbbi5 Firmware, Intel Nuc 13 Extreme Compute Element Nuc13Sbbi5, Intel Nuc 13 Extreme Compute Element Nuc13Sbbi5F Firmware, Intel Nuc 13 Extreme Compute Element Nuc13Sbbi5F, Intel Nuc 13 Extreme Compute Element Nuc13Sbbi7 Firmware.