MEDIUM · 4.6

CVE-2023-25756

Out-of-bounds read in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via adjacent access.

Vulnerability Description

Out-of-bounds read in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via adjacent access.

CVSS Score

4.6

MEDIUM

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
NONE
Availability
LOW

Affected Products

VendorProductVersions
IntelAtom X6200Fe Firmware-
IntelAtom X6200Fe-
IntelAtom X6211E Firmware-
IntelAtom X6211E-
IntelAtom X6212Re Firmware-
IntelAtom X6212Re-
IntelAtom X6413E Firmware-
IntelAtom X6413E-
IntelAtom X6414Re Firmware-
IntelAtom X6414Re-
IntelAtom X6425E Firmware-
IntelAtom X6425E-
IntelAtom X6425Re Firmware-
IntelAtom X6425Re-
IntelAtom X6427Fe Firmware-
IntelAtom X6427Fe-
IntelCeleron 1000M Firmware-
IntelCeleron 1000M-
IntelCeleron 1005M Firmware-
IntelCeleron 1005M-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-25756?

CVE-2023-25756 is a vulnerability with a CVSS score of 4.6 (MEDIUM). Out-of-bounds read in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via adjacent access.

How severe is CVE-2023-25756?

CVE-2023-25756 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-25756?

Check the references section above for vendor advisories and patch information. Affected products include: Intel Atom X6200Fe Firmware, Intel Atom X6200Fe, Intel Atom X6211E Firmware, Intel Atom X6211E, Intel Atom X6212Re Firmware.