7.8

CVE-2023-22312

Improper access control for some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.

Data is provided by the National Vulnerability Database (NVD)
IntelNuc M15 Laptop Kit Lapbc710 Firmware Version < bctgl357.0078
IntelNuc M15 Laptop Kit Lapbc510 Firmware Version < bctgl357.0078
IntelLapkc51e Firmware Version < kctgl357.0044
   IntelLapkc51e Version-
IntelLapkc71e Firmware Version < kctgl357.0044
   IntelLapkc71e Version-
IntelLapkc71f Firmware Version < kctgl357.0044
   IntelLapkc71f Version-
IntelNuc11btmi7 Firmware Version < dbtgl579.0065
   IntelNuc11btmi7 Version-
IntelNuc11dbbi7 Firmware Version < dbtgl579.0065
   IntelNuc11dbbi7 Version-
IntelNuc11btmi9 Firmware Version < dbtgl579.0065
   IntelNuc11btmi9 Version-
IntelNuc11dbbi9 Firmware Version < dbtgl579.0065
   IntelNuc11dbbi9 Version-
IntelNuc Board Nuc8cchb Firmware Version < chaplcel.0061
   IntelNuc Board Nuc8cchb Version-
IntelNuc 8 Rugged Board Nuc8cchbn Firmware Version < chaplcel.0061
IntelNuc 8 Rugged Kit Nuc8cchkrn Firmware Version < chaplcel.0061
IntelNuc 8 Rugged Kit Nuc8cchkr Firmware Version < chaplcel.0061
   IntelNuc 8 Rugged Kit Nuc8cchkr Version-
IntelNuc 11 Pro Kit Nuc11tnkv50z Firmware Version < tntglv57.0071
IntelNuc 11 Pro Kit Nuc11tnhv70l Firmware Version < tntglv57.0071
IntelNuc 11 Pro Kit Nuc11tnhv50l Firmware Version < tntglv57.0071
IntelNuc 11 Pro Board Nuc11tnbv7 Firmware Version < tntglv57.0071
IntelNuc 11 Pro Kit Nuc11tnkv5 Firmware Version < tntglv57.0071
   IntelNuc 11 Pro Kit Nuc11tnkv5 Version-
IntelNuc 11 Pro Kit Nuc11tnkv7 Firmware Version < tntglv57.0071
   IntelNuc 11 Pro Kit Nuc11tnkv7 Version-
IntelNuc 11 Pro Kit Nuc11tnhv5 Firmware Version < tntglv57.0071
   IntelNuc 11 Pro Kit Nuc11tnhv5 Version-
IntelNuc 11 Pro Kit Nuc11tnhv7 Firmware Version < tntglv57.0071
   IntelNuc 11 Pro Kit Nuc11tnhv7 Version-
IntelNuc 11 Pro Board Nuc11tnbv5 Firmware Version < tntglv57.0071
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.07% 0.195
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
secure@intel.com 7.2 0.6 6
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.