cbcvebase.
CVE-2022-24382
published 2022-05-12

CVE-2022-24382: Improper input validation in firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access.

PriorityP425medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.23%
13.5th percentile
Improper input validation in firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access.

Affected

59 ranges· showing 25
VendorProductVersion rangeFixed in
intellapbc510_firmware< bctgl357.0065bctgl357.0065
intellapbc710_firmware< bctgl357.0065bctgl357.0065
intellapkc51e_firmware< kctgl357.0040kctgl357.0040
intellapkc71e_firmware< kctgl357.0040kctgl357.0040
intellapkc71f_firmware< kctgl357.0040kctgl357.0040
intelnuc11btmi7_firmware< dbtgl579.0055dbtgl579.0055
intelnuc11btmi9_firmware< dbtgl579.0055dbtgl579.0055
intelnuc11dbbi7_firmware< dbtgl579.0055dbtgl579.0055
intelnuc11dbbi9_firmware< dbtgl579.0055dbtgl579.0055
intelnuc11pa_firmware< patgl357.0042patgl357.0042
intelnuc11pah_firmware< patgl357.0042patgl357.0042
intelnuc11paq_firmware< patgl357.0042patgl357.0042
intelnuc8i3cysm_firmware< cycnli35.86a.0050cycnli35.86a.0050
intelnuc8i3cysn_firmware< cycnli35.86a.0050cycnli35.86a.0050
intelnuc9i5qn_firmware< qxcfl579.0064qxcfl579.0064
intelnuc9i7qn_firmware< qxcfl579.0064qxcfl579.0064
intelnuc9i9qn_firmware< qxcfl579.0064qxcfl579.0064
intelnuc_11_compute_element_cm11ebc4w_firmware< ebtgl357.0057ebtgl357.0057
intelnuc_11_compute_element_cm11ebi38w_firmware< ebtgl357.0057ebtgl357.0057
intelnuc_11_compute_element_cm11ebi58w_firmware< ebtgl357.0057ebtgl357.0057
intelnuc_11_compute_element_cm11ebi716w_firmware< ebtgl357.0057ebtgl357.0057
intelnuc_11_enthusiast_kit_nuc11phki7c_firmware< phtgl579.0064phtgl579.0064
intelnuc_11_enthusiast_mini_pc_nuc11phki7caa_firmware< phtgl579.0064phtgl579.0064
intelnuc_11_pro_board_nuc11tnbi30z_firmware< tntgl357.0059tntgl357.0059
intelnuc_11_pro_board_nuc11tnbi3_firmware< tntgl357.0059tntgl357.0059

CVSS provenance

nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.