CVE-2022-36789Improper Access Control in Intel NUC 10 Performance KIT Nuc10i3fnh Firmware

Severity
7.8HIGHNVD
CNA7.5
EPSS
0.0%
top 85.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 11

Description

Improper access control in BIOS firmware for some Intel(R) NUC 10 Performance Kits and Intel(R) NUC 10 Performance Mini PCs before version FNCML357.0053 may allow a privileged user to potentially enable escalation of privilege via local access.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

🔴Vulnerability Details

2
GHSA
GHSA-pmvv-r44r-j4g9: Improper access control in BIOS firmware for some Intel(R) NUC 10 Performance Kits and Intel(R) NUC 10 Performance Mini PCs before version FNCML3572022-11-11
CVEList
CVE-2022-36789: Improper access control in BIOS firmware for some Intel(R) NUC 10 Performance Kits and Intel(R) NUC 10 Performance Mini PCs before version FNCML3572022-11-11
CVE-2022-36789 — Improper Access Control in Intel | cvebase