CVE-2023-22449
high-risk
Published 2023-08-11
Improper input validation in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.
Do I need to act?
-
0.03% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.5/10
High
LOCAL
/ HIGH complexity
Affected Products (20)
Nuc 13 Extreme Compute Element Nuc13Sbbi5 Firmware
Nuc 13 Extreme Compute Element Nuc13Sbbi5F Firmware
Nuc 13 Extreme Compute Element Nuc13Sbbi7 Firmware
Nuc 13 Extreme Compute Element Nuc13Sbbi7F Firmware
Nuc 13 Extreme Compute Element Nuc13Sbbi9 Firmware
Nuc 13 Extreme Compute Element Nuc13Sbbi9F Firmware
Nuc 13 Extreme Kit Nuc13Rngi5 Firmware
Nuc 13 Extreme Kit Nuc13Rngi7 Firmware
Nuc 13 Extreme Kit Nuc13Rngi9 Firmware
Nuc 11 Performance Kit Nuc11Pahi3 Firmware
Nuc 11 Performance Kit Nuc11Pahi30Z Firmware
Nuc 11 Performance Kit Nuc11Paki3 Firmware
Nuc 11 Performance Kit Nuc11Pahi5 Firmware
Nuc 11 Performance Kit Nuc11Pahi50Z Firmware
Nuc 11 Performance Kit Nuc11Paki5 Firmware
Nuc 11 Performance Kit Nuc11Paqi50Wa Firmware
Nuc 11 Performance Kit Nuc11Pahi7 Firmware
Nuc 11 Performance Kit Nuc11Pahi70Z Firmware
Nuc 11 Performance Kit Nuc11Paki7 Firmware
Nuc 11 Performance Kit Nuc11Paqi70Qa Firmware
Affected Vendors
53
/ 100
high-risk
Severity
20/34 · Moderate
Exploitability
0/34 · Minimal
Exposure
33/34 · Critical