CVE-2022-21933
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
ASUS VivoMini/Mini PC device has an improper input validation vulnerability. A local attacker with system privilege can use system management interrupt (SMI) to modify memory, resulting in arbitrary code execution for controlling the system or disrupting service.
Affected (13)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1302 |
| Running on/with | Platform Versions |
|---|---|
Asus Vc65 C1 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1302 |
| Running on/with | Platform Versions |
|---|---|
Asus Pb60v | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1302 |
| Running on/with | Platform Versions |
|---|---|
Asus Pb60g | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1302 |
| Running on/with | Platform Versions |
|---|---|
Asus Pb60s | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1401 |
| Running on/with | Platform Versions |
|---|---|
Asus Pa90 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 902 |
| Running on/with | Platform Versions |
|---|---|
Asus Pb50 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1502 |
| Running on/with | Platform Versions |
|---|---|
Asus Pb60 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 601 |
| Running on/with | Platform Versions |
|---|---|
Asus Pb61v | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 609 |
| Running on/with | Platform Versions |
|---|---|
Asus Ts10 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2201 |
| Running on/with | Platform Versions |
|---|---|
Asus Pn40 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 808 |
| Running on/with | Platform Versions |
|---|---|
Asus Pn60 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 320 |
| Running on/with | Platform Versions |
|---|---|
Asus Pn30 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 618 |
| Running on/with | Platform Versions |
|---|---|
Asus Un65u | All versions |
Related CWEs
CWE-20
Improper Input Validation
The product receives input or data, but it does
not validate or incorrectly validates that the input has the
properties that are required to process the data safely and
correctly.
CWE-787
Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.