7.5

CVE-2022-30539

Use after free in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IntelXeon Gold 5315y Firmware Version-
   IntelXeon Gold 5315y Version-
IntelXeon Gold 5317 Firmware Version-
   IntelXeon Gold 5317 Version-
IntelXeon Gold 5318n Firmware Version-
   IntelXeon Gold 5318n Version-
IntelXeon Gold 5318s Firmware Version-
   IntelXeon Gold 5318s Version-
IntelXeon Gold 5318y Firmware Version-
   IntelXeon Gold 5318y Version-
IntelXeon Gold 5320 Firmware Version-
   IntelXeon Gold 5320 Version-
IntelXeon Gold 5320t Firmware Version-
   IntelXeon Gold 5320t Version-
IntelXeon Gold 6312u Firmware Version-
   IntelXeon Gold 6312u Version-
IntelXeon Gold 6314u Firmware Version-
   IntelXeon Gold 6314u Version-
IntelXeon Gold 6326 Firmware Version-
   IntelXeon Gold 6326 Version-
IntelXeon Gold 6330 Firmware Version-
   IntelXeon Gold 6330 Version-
IntelXeon Gold 6330n Firmware Version-
   IntelXeon Gold 6330n Version-
IntelXeon Gold 6334 Firmware Version-
   IntelXeon Gold 6334 Version-
IntelXeon Gold 6336y Firmware Version-
   IntelXeon Gold 6336y Version-
IntelXeon Gold 6338 Firmware Version-
   IntelXeon Gold 6338 Version-
IntelXeon Gold 6338n Firmware Version-
   IntelXeon Gold 6338n Version-
IntelXeon Gold 6338t Firmware Version-
   IntelXeon Gold 6338t Version-
IntelXeon Gold 6342 Firmware Version-
   IntelXeon Gold 6342 Version-
IntelXeon Gold 6346 Firmware Version-
   IntelXeon Gold 6346 Version-
IntelXeon Gold 6348 Firmware Version-
   IntelXeon Gold 6348 Version-
IntelXeon Gold 6354 Firmware Version-
   IntelXeon Gold 6354 Version-
IntelXeon Platinum 8358 Firmware Version-
   IntelXeon Platinum 8358 Version-
IntelXeon Platinum 8362 Firmware Version-
   IntelXeon Platinum 8362 Version-
IntelXeon Platinum 8368 Firmware Version-
   IntelXeon Platinum 8368 Version-
IntelXeon Platinum 8380 Firmware Version-
   IntelXeon Platinum 8380 Version-
IntelXeon Silver 4309y Firmware Version-
   IntelXeon Silver 4309y Version-
IntelXeon Silver 4310 Firmware Version-
   IntelXeon Silver 4310 Version-
IntelXeon Silver 4310t Firmware Version-
   IntelXeon Silver 4310t Version-
IntelXeon Silver 4314 Firmware Version-
   IntelXeon Silver 4314 Version-
IntelXeon Silver 4316 Firmware Version-
   IntelXeon Silver 4316 Version-
IntelXeon Gold 6330h Firmware Version-
   IntelXeon Gold 6330h Version-
IntelXeon Gold 5318h Firmware Version-
   IntelXeon Gold 5318h Version-
IntelXeon Gold 5320h Firmware Version-
   IntelXeon Gold 5320h Version-
IntelXeon Gold 6328h Firmware Version-
   IntelXeon Gold 6328h Version-
IntelXeon Gold 6328hl Firmware Version-
   IntelXeon Gold 6328hl Version-
IntelXeon Gold 6348h Firmware Version-
   IntelXeon Gold 6348h Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.05% 0.156
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
secure@intel.com 7.5 0.8 6
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
CWE-416 Use After Free

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.