CVE-2022-27229
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
Path transversal in some Intel(R) NUC Kits NUC7i3DN, NUC7i5DN, NUC7i7DN HDMI firmware update tool software before version 1.79.1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
Affected (1)
Products: Intel: Hdmi Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.79.1.1 |
| Running on/with | Platform Versions |
|---|---|
Intel Nuc 7 Business Nuc7i3dnhnc | All versions |
Intel Nuc 7 Business Nuc7i3dnktc | All versions |
Intel Nuc 7 Business Nuc7i5dnkpc | All versions |
Intel Nuc 7 Business Nuc7i5dnkpu | All versions |
Intel Nuc Kit Nuc7i3dnhe | All versions |
Intel Nuc Kit Nuc7i3dnke | All versions |
Intel Nuc Kit Nuc7i5dnhe | All versions |
Intel Nuc Kit Nuc7i5dnke | All versions |
Intel Nuc Kit Nuc7i7dnhe | All versions |
Intel Nuc Kit Nuc7i7dnke | All versions |
Related CWEs
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CWE-249
DEPRECATED: Often Misused: Path Manipulation
This entry has been deprecated because of name
confusion and an accidental combination of multiple
weaknesses. Most of its content has been transferred to
CWE-785.
References (2)
Source: secure@intel.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Timeline
No history available yet.