cbcvebase.
CVE-2022-21181
published 2022-08-18

CVE-2022-21181: Improper input validation for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow a privileged user to potentially enable escalation of…

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
Improper input validation for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow a privileged user to potentially enable escalation of privilege via local access.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianfirmware-nonfree< firmware-nonfree 20220913-1 (bookworm)firmware-nonfree 20220913-1 (bookworm)
inteldual_band_wireless-ac_8260_firmware< 22.12022.120
inteldual_band_wireless-ac_8265_firmware< 22.12022.120
intelkiller_ac_1550_firmware< 3.1122.11053.1122.1105
intelwireless-ac_9260_firmware< 22.12022.120
intelwireless-ac_9461_firmware< 22.12022.120
intelwireless-ac_9462_firmware< 22.12022.120
intelwireless-ac_9560_firmware< 22.12022.120
intel_prosetwireless_wifi_and_killer_wifi_products

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH