CVE-2023-22312
moderate-risk
Published 2023-05-10
Improper access control for some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.
Do I need to act?
-
0.09% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.2/10
High
LOCAL
/ HIGH complexity
Affected Products (20)
Nuc 11 Performance Kit Nuc11Pahi70Z Firmware
Nuc 11 Performance Kit Nuc11Pahi50Z Firmware
Nuc 11 Performance Kit Nuc11Pahi30Z Firmware
Nuc 11 Performance Kit Nuc11Pahi3 Firmware
Nuc 11 Performance Kit Nuc11Pahi5 Firmware
Nuc 11 Performance Kit Nuc11Pahi7 Firmware
Nuc 11 Performance Kit Nuc11Paki3 Firmware
Nuc 11 Performance Kit Nuc11Paki5 Firmware
Nuc 11 Performance Kit Nuc11Paki7 Firmware
Nuc 11 Performance Mini Pc Nuc11Paqi50Wa Firmware
Nuc 11 Performance Mini Pc Nuc11Paqi70Qa Firmware
Nuc 11 Compute Element Cm11Ebi38W Firmware
Nuc 11 Compute Element Cm11Ebi58W Firmware
Nuc 11 Compute Element Cm11Ebi716W Firmware
Nuc 11 Compute Element Cm11Ebc4W Firmware
Nuc M15 Laptop Kit Lapbc710 Firmware
Nuc M15 Laptop Kit Lapbc510 Firmware
Lapkc51E Firmware
Lapkc71E Firmware
Lapkc71F Firmware
Affected Vendors
43
/ 100
moderate-risk
Severity
19/34 · Moderate
Exploitability
0/34 · Minimal
Exposure
24/34 · High