7.8

CVE-2022-38787

Improper input validation in firmware for some Intel(R) FPGA products before version 2.7.0 Hotfix may allow an authenticated user to potentially enable escalation of privilege via local access.

Data is provided by the National Vulnerability Database (NVD)
IntelStratix 10 Nx 2100 Fpga Firmware Version <= 2.7.0
   IntelStratix 10 Nx 2100 Fpga Version-
IntelStratix 10 Dx 2800 Fpga Firmware Version <= 2.7.0
   IntelStratix 10 Dx 2800 Fpga Version-
IntelStratix 10 Dx 2100 Fpga Firmware Version <= 2.7.0
   IntelStratix 10 Dx 2100 Fpga Version-
IntelStratix 10 Dx 1100 Fpga Firmware Version <= 2.7.0
   IntelStratix 10 Dx 1100 Fpga Version-
IntelStratix 10 Tx 1650 Fpga Firmware Version <= 2.7.0
   IntelStratix 10 Tx 1650 Fpga Version-
IntelStratix 10 Tx 2500 Fpga Firmware Version <= 2.7.0
   IntelStratix 10 Tx 2500 Fpga Version-
IntelStratix 10 Tx 2100 Fpga Firmware Version <= 2.7.0
   IntelStratix 10 Tx 2100 Fpga Version-
IntelStratix 10 Tx 850 Fpga Firmware Version <= 2.7.0
   IntelStratix 10 Tx 850 Fpga Version-
IntelStratix 10 Tx 400 Fpga Firmware Version <= 2.7.0
   IntelStratix 10 Tx 400 Fpga Version-
IntelStratix 10 Tx 1100 Fpga Firmware Version <= 2.7.0
   IntelStratix 10 Tx 1100 Fpga Version-
IntelStratix 10 Tx 2800 Fpga Firmware Version <= 2.7.0
   IntelStratix 10 Tx 2800 Fpga Version-
IntelStratix 10 Sx 650 Fpga Firmware Version <= 2.7.0
   IntelStratix 10 Sx 650 Fpga Version-
IntelStratix 10 Sx 400 Fpga Firmware Version <= 2.7.0
   IntelStratix 10 Sx 400 Fpga Version-
IntelStratix 10 Sx 1100 Fpga Firmware Version <= 2.7.0
   IntelStratix 10 Sx 1100 Fpga Version-
IntelStratix 10 Sx 850 Fpga Firmware Version <= 2.7.0
   IntelStratix 10 Sx 850 Fpga Version-
IntelStratix 10 Sx 1650 Fpga Firmware Version <= 2.7.0
   IntelStratix 10 Sx 1650 Fpga Version-
IntelStratix 10 Sx 2100 Fpga Firmware Version <= 2.7.0
   IntelStratix 10 Sx 2100 Fpga Version-
IntelStratix 10 Sx 2500 Fpga Firmware Version <= 2.7.0
   IntelStratix 10 Sx 2500 Fpga Version-
IntelStratix 10 Sx 2800 Fpga Firmware Version <= 2.7.0
   IntelStratix 10 Sx 2800 Fpga Version-
IntelStratix 10 Mx 2100 Fpga Firmware Version <= 2.7.0
   IntelStratix 10 Mx 2100 Fpga Version-
IntelStratix 10 Mx 1650 Fpga Firmware Version <= 2.7.0
   IntelStratix 10 Mx 1650 Fpga Version-
IntelStratix 10 Gx 2110 Fpga Firmware Version <= 2.7.0
   IntelStratix 10 Gx 2110 Fpga Version-
IntelStratix 10 Gx 1660 Fpga Firmware Version <= 2.7.0
   IntelStratix 10 Gx 1660 Fpga Version-
IntelStratix 10 Gx 650 Fpga Firmware Version <= 2.7.0
   IntelStratix 10 Gx 650 Fpga Version-
IntelStratix 10 Gx 400 Fpga Firmware Version <= 2.7.0
   IntelStratix 10 Gx 400 Fpga Version-
IntelStratix 10 Gx 850 Fpga Firmware Version <= 2.7.0
   IntelStratix 10 Gx 850 Fpga Version-
IntelStratix 10 Gx 2100 Fpga Firmware Version <= 2.7.0
   IntelStratix 10 Gx 2100 Fpga Version-
IntelStratix 10 Gx 1100 Fpga Firmware Version <= 2.7.0
   IntelStratix 10 Gx 1100 Fpga Version-
IntelStratix 10 Gx 2500 Fpga Firmware Version <= 2.7.0
   IntelStratix 10 Gx 2500 Fpga Version-
IntelStratix 10 Gx 10m Fpga Firmware Version <= 2.7.0
   IntelStratix 10 Gx 10m Fpga Version-
IntelStratix 10 Gx 2800 Fpga Firmware Version <= 2.7.0
   IntelStratix 10 Gx 2800 Fpga Version-
IntelStratix 10 Gx 1650 Fpga Firmware Version <= 2.7.0
   IntelStratix 10 Gx 1650 Fpga Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.04% 0.07
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
secure@intel.com 5.7 0.5 5.2
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.