CVE-2023-22312

moderate-risk
Published 2023-05-10

Improper access control for some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.

Do I need to act?

-
0.09% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.2/10 High
LOCAL / HIGH complexity

Affected Products (20)

Nuc 11 Performance Kit Nuc11Pahi70Z Firmware
Nuc 11 Performance Kit Nuc11Pahi50Z Firmware
Nuc 11 Performance Kit Nuc11Pahi30Z Firmware
Nuc 11 Performance Kit Nuc11Pahi3 Firmware
Nuc 11 Performance Kit Nuc11Pahi5 Firmware
Nuc 11 Performance Kit Nuc11Pahi7 Firmware
Nuc 11 Performance Kit Nuc11Paki3 Firmware
Nuc 11 Performance Kit Nuc11Paki5 Firmware
Nuc 11 Performance Kit Nuc11Paki7 Firmware
Nuc 11 Performance Mini Pc Nuc11Paqi50Wa Firmware
Nuc 11 Performance Mini Pc Nuc11Paqi70Qa Firmware
Nuc 11 Compute Element Cm11Ebi38W Firmware
Nuc 11 Compute Element Cm11Ebi58W Firmware
Nuc 11 Compute Element Cm11Ebi716W Firmware
Nuc 11 Compute Element Cm11Ebc4W Firmware
Nuc M15 Laptop Kit Lapbc710 Firmware
Nuc M15 Laptop Kit Lapbc510 Firmware
Lapkc51E Firmware
Lapkc71E Firmware
Lapkc71F Firmware

Affected Vendors

43
/ 100
moderate-risk
Severity 19/34 · Moderate
Exploitability 0/34 · Minimal
Exposure 24/34 · High