HIGH · 7.5

CVE-2023-22449

Improper input validation in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.

Vulnerability Description

Improper input validation in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
IntelNuc 13 Extreme Compute Element Nuc13Sbbi5 Firmware-
IntelNuc 13 Extreme Compute Element Nuc13Sbbi5-
IntelNuc 13 Extreme Compute Element Nuc13Sbbi5F Firmware-
IntelNuc 13 Extreme Compute Element Nuc13Sbbi5F-
IntelNuc 13 Extreme Compute Element Nuc13Sbbi7 Firmware-
IntelNuc 13 Extreme Compute Element Nuc13Sbbi7-
IntelNuc 13 Extreme Compute Element Nuc13Sbbi7F Firmware-
IntelNuc 13 Extreme Compute Element Nuc13Sbbi7F-
IntelNuc 13 Extreme Compute Element Nuc13Sbbi9 Firmware-
IntelNuc 13 Extreme Compute Element Nuc13Sbbi9-
IntelNuc 13 Extreme Compute Element Nuc13Sbbi9F Firmware-
IntelNuc 13 Extreme Compute Element Nuc13Sbbi9F-
IntelNuc 13 Extreme Kit Nuc13Rngi5 Firmware-
IntelNuc 13 Extreme Kit Nuc13Rngi5-
IntelNuc 13 Extreme Kit Nuc13Rngi7 Firmware-
IntelNuc 13 Extreme Kit Nuc13Rngi7-
IntelNuc 13 Extreme Kit Nuc13Rngi9 Firmware-
IntelNuc 13 Extreme Kit Nuc13Rngi9-
IntelNuc 11 Performance Kit Nuc11Pahi3 Firmware-
IntelNuc 11 Performance Kit Nuc11Pahi3-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-22449?

CVE-2023-22449 is a vulnerability with a CVSS score of 7.5 (HIGH). Improper input validation in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.

How severe is CVE-2023-22449?

CVE-2023-22449 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-22449?

Check the references section above for vendor advisories and patch information. Affected products include: Intel Nuc 13 Extreme Compute Element Nuc13Sbbi5 Firmware, Intel Nuc 13 Extreme Compute Element Nuc13Sbbi5, Intel Nuc 13 Extreme Compute Element Nuc13Sbbi5F Firmware, Intel Nuc 13 Extreme Compute Element Nuc13Sbbi5F, Intel Nuc 13 Extreme Compute Element Nuc13Sbbi7 Firmware.