Improper input validation for some Intel NUC BIOS firmware before version JY0070 may allow a privileged user to potentially enable escalation of privilege via local access.
References
Link | Resource |
---|---|
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01009.html | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
History
30 Jan 2024, 15:18
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
CWE | CWE-20 | |
First Time |
Intel nuc Kit Nuc7cjysal
Intel nuc Kit Nuc7cjyh Firmware Intel nuc 7 Essential Nuc7cjysamn Firmware Intel nuc 7 Essential Nuc7cjysamn Intel nuc Kit Nuc7pjyh Intel Intel nuc Kit Nuc7cjyhn Intel nuc Kit Nuc7pjyhn Firmware Intel nuc Kit Nuc7cjyh Intel nuc Kit Nuc7pjyhn Intel nuc Kit Nuc7pjyh Firmware Intel nuc Kit Nuc7cjysal Firmware Intel nuc Kit Nuc7cjyhn Firmware |
|
References | () https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01009.html - Vendor Advisory | |
CPE | cpe:2.3:h:intel:nuc_kit_nuc7cjysal:-:*:*:*:*:*:*:* cpe:2.3:h:intel:nuc_kit_nuc7pjyh:-:*:*:*:*:*:*:* cpe:2.3:h:intel:nuc_kit_nuc7cjyh:-:*:*:*:*:*:*:* cpe:2.3:o:intel:nuc_kit_nuc7pjyhn_firmware:jyglkcpx.0071:*:*:*:*:*:*:* cpe:2.3:h:intel:nuc_kit_nuc7pjyhn:-:*:*:*:*:*:*:* cpe:2.3:o:intel:nuc_kit_nuc7cjyh_firmware:jyglkcpx.0071:*:*:*:*:*:*:* cpe:2.3:o:intel:nuc_kit_nuc7pjyh_firmware:jyglkcpx.0071:*:*:*:*:*:*:* cpe:2.3:h:intel:nuc_kit_nuc7cjyhn:-:*:*:*:*:*:*:* cpe:2.3:o:intel:nuc_kit_nuc7cjyhn_firmware:jyglkcpx.0071:*:*:*:*:*:*:* cpe:2.3:o:intel:nuc_kit_nuc7cjysal_firmware:jyglkcpx.0071:*:*:*:*:*:*:* cpe:2.3:o:intel:nuc_7_essential_nuc7cjysamn_firmware:jyglkcpx.0071:*:*:*:*:*:*:* cpe:2.3:h:intel:nuc_7_essential_nuc7cjysamn:-:*:*:*:*:*:*:* |
19 Jan 2024, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-01-19 20:15
Updated : 2024-10-21 12:35
NVD link : CVE-2023-28738
Mitre link : CVE-2023-28738
JSON object : View
Products Affected
intel
- nuc_7_essential_nuc7cjysamn_firmware
- nuc_kit_nuc7cjyhn
- nuc_kit_nuc7pjyh
- nuc_kit_nuc7pjyhn_firmware
- nuc_kit_nuc7pjyh_firmware
- nuc_kit_nuc7cjyhn_firmware
- nuc_kit_nuc7cjyh
- nuc_kit_nuc7cjyh_firmware
- nuc_kit_nuc7cjysal
- nuc_kit_nuc7cjysal_firmware
- nuc_7_essential_nuc7cjysamn
- nuc_kit_nuc7pjyhn
CWE
CWE-20
Improper Input Validation