7.8

CVE-2022-21933

ASUS VivoMini/Mini PC device has an improper input validation vulnerability. A local attacker with system privilege can use system management interrupt (SMI) to modify memory, resulting in arbitrary code execution for controlling the system or disrupting service.

Data is provided by the National Vulnerability Database (NVD)
AsusVc65-c1 Firmware Version < 1302
   AsusVc65-c1 Version-
AsusPb60v Firmware Version < 1302
   AsusPb60v Version-
AsusPb60g Firmware Version < 1302
   AsusPb60g Version-
AsusPb60s Firmware Version < 1302
   AsusPb60s Version-
AsusPa90 Firmware Version < 1401
   AsusPa90 Version-
AsusPb50 Firmware Version < 902
   AsusPb50 Version-
AsusPb60 Firmware Version < 1502
   AsusPb60 Version-
AsusPb61v Firmware Version < 601
   AsusPb61v Version-
AsusTs10 Firmware Version < 609
   AsusTs10 Version-
AsusPn40 Firmware Version < 2201
   AsusPn40 Version-
AsusPn60 Firmware Version < 808
   AsusPn60 Version-
AsusPn30 Firmware Version < 320
   AsusPn30 Version-
AsusUn65u Firmware Version < 618
   AsusUn65u Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.05% 0.154
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
twcert@cert.org.tw 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.