CVE-2023-34438

moderate-risk
Published 2023-08-11

Race condition in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.

Do I need to act?

-
0.03% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.5/10 High
LOCAL / HIGH complexity

Affected Products (20)

Nuc Rugged Kit Nuc8Cchb Firmware
Nuc Rugged Kit Nuc8Cchbn Firmware
Nuc Rugged Kit Nuc8Cchkrn Firmware
Nuc Rugged Kit Nuc8Cchkr Firmware
Nuc Kit Nuc6Cayh Firmware
Nuc Kit Nuc6Cays Firmware
Nuc Mini Pc Nuc7I3Bnhxf Firmware
Nuc Mini Pc Nuc7I3Bnk Firmware
Nuc Mini Pc Nuc7I3Bnh Firmware
Nuc Mini Pc Nuc7I3Bnb Firmware
Nuc Mini Pc Nuc7I5Bnhx1 Firmware
Nuc Mini Pc Nuc7I5Bnh Firmware
Nuc Mini Pc Nuc7I5Bnk Firmware
Nuc Mini Pc Nuc7I5Bnhxf Firmware
Nuc Mini Pc Nuc7I5Bnkp Firmware
Nuc Mini Pc Nuc7I5Bnb Firmware
Nuc Mini Pc Nuc7I7Bnh Firmware
Nuc Mini Pc Nuc7I7Bnhx1 Firmware
Nuc Mini Pc Nuc7I7Bnhxg Firmware
Nuc Mini Pc Nuc7I3Bnhx1 Firmware

Affected Vendors

48
/ 100
moderate-risk
Severity 20/34 · Moderate
Exploitability 0/34 · Minimal
Exposure 28/34 · Critical