CVE-2022-37327
Improper input validation in BIOS firmware for Intel(R) NUC, Intel(R) NUC Performance Kit, Intel(R) NUC Performance Mini PC, Intel(R) NUC 8 Compute Element, Intel(R) NUC Pro Kit, Intel(R) NUC Pro Board, Intel(R) NUC 11 Compute Element, Intel(R) NUC 12…
Does this matter?
Lower severity and a low EPSS score (0.18%). Track it; it rarely justifies an emergency change on its own.
Description
Improper input validation in BIOS firmware for Intel(R) NUC, Intel(R) NUC Performance Kit, Intel(R) NUC Performance Mini PC, Intel(R) NUC 8 Compute Element, Intel(R) NUC Pro Kit, Intel(R) NUC Pro Board, Intel(R) NUC 11 Compute Element, Intel(R) NUC 12 Compute Element, Intel(R) NUC Extreme, Intel(R) NUC 12 Extreme Compute Element, Intel(R) NUC Laptop Kit, Intel(R) NUC Enthusiast, Intel(R) NUC Essential, Intel(R) NUC Laptop Kit, Intel(R) NUC Extreme Compute Element, Intel(R) NUC Boards, Intel(R) NUC Pro Compute Element, Intel(R) NUC Rugged may allow a privileged user to enable information disclosure via local access.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.18% probability · 7th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- intel/nuc10i3fnh firmware · intel/nuc10i3fnhf firmware · intel/nuc10i3fnhfa firmware · intel/nuc10i3fnhja firmware · intel/nuc10i3fnhn firmware · intel/nuc10i3fnk firmware · intel/nuc10i3fnkn firmware · intel/nuc10i5fnh firmware · intel/nuc10i5fnhca firmware · intel/nuc10i5fnhf firmware · intel/nuc10i5fnhja firmware · intel/nuc10i5fnhj firmware · intel/nuc10i5fnhn firmware · intel/nuc10i5fnk firmware · intel/nuc10i5fnkn firmware · intel/nuc10i5fnkpa firmware · intel/nuc10i5fnkp firmware · intel/nuc10i7fnh firmware · intel/nuc10i7fnhaa firmware · intel/nuc10i7fnhc firmware · +40 more
- Source
- secure@intel.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.