MEDIUM · 4.6

CVE-2023-34349

Race condition in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.

Vulnerability Description

Race condition in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.

CVSS Score

4.6

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
CHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
IntelNuc Performance Kit And Mini Pc Nuc10I3Fnh Firmware-
IntelNuc Performance Kit And Mini Pc Nuc10I3Fnh-
IntelNuc Performance Kit And Mini Pc Nuc10I3Fnhf Firmware-
IntelNuc Performance Kit And Mini Pc Nuc10I3Fnhf-
IntelNuc Performance Kit And Mini Pc Nuc10I3Fnhfa Firmware-
IntelNuc Performance Kit And Mini Pc Nuc10I3Fnhfa-
IntelNuc Performance Kit And Mini Pc Nuc10I3Fnhja Firmware-
IntelNuc Performance Kit And Mini Pc Nuc10I3Fnhja-
IntelNuc Performance Kit And Mini Pc Nuc10I3Fnhn Firmware-
IntelNuc Performance Kit And Mini Pc Nuc10I3Fnhn-
IntelNuc Performance Kit And Mini Pc Nuc10I3Fnk Firmware-
IntelNuc Performance Kit And Mini Pc Nuc10I3Fnk-
IntelNuc Performance Kit And Mini Pc Nuc10I3Fnkn Firmware-
IntelNuc Performance Kit And Mini Pc Nuc10I3Fnkn-
IntelNuc Performance Kit And Mini Pc Nuc10I5Fnh Firmware-
IntelNuc Performance Kit And Mini Pc Nuc10I5Fnh-
IntelNuc Performance Kit And Mini Pc Nuc10I5Fnhca Firmware-
IntelNuc Performance Kit And Mini Pc Nuc10I5Fnhca-
IntelNuc Performance Kit And Mini Pc Nuc10I5Fnhf Firmware-
IntelNuc Performance Kit And Mini Pc Nuc10I5Fnhf-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-34349?

CVE-2023-34349 is a vulnerability with a CVSS score of 4.6 (MEDIUM). Race condition in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.

How severe is CVE-2023-34349?

CVE-2023-34349 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-34349?

Check the references section above for vendor advisories and patch information. Affected products include: Intel Nuc Performance Kit And Mini Pc Nuc10I3Fnh Firmware, Intel Nuc Performance Kit And Mini Pc Nuc10I3Fnh, Intel Nuc Performance Kit And Mini Pc Nuc10I3Fnhf Firmware, Intel Nuc Performance Kit And Mini Pc Nuc10I3Fnhf, Intel Nuc Performance Kit And Mini Pc Nuc10I3Fnhfa Firmware.