cbcvebase.
CVE-2022-21794
published 2022-11-11

CVE-2022-21794: Improper authentication in BIOS firmware for some Intel(R) NUC Boards, Intel(R) NUC Business, Intel(R) NUC Enthusiast, Intel(R) NUC Kits before version HN0067…

PriorityP425medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.19%
8.8th percentile
Improper authentication in BIOS firmware for some Intel(R) NUC Boards, Intel(R) NUC Business, Intel(R) NUC Enthusiast, Intel(R) NUC Kits before version HN0067 may allow a privileged user to potentially enable escalation of privilege via local access.

Affected

5 ranges
VendorProductVersion rangeFixed in
intelnuc_8_business_nuc8i7hnkqc_firmware< hn0067hn0067
intelnuc_8_enthusiast_nuc8i7hvkva_firmware< hn0067hn0067
intelnuc_8_enthusiast_nuc8i7hvkvaw_firmware< hn0067hn0067
intelnuc_kit_nuc8i7hnk_firmware< hn0067hn0067
intelnuc_kit_nuc8i7hvk_firmware< hn0067hn0067
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.