CVE-2023-38587
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
Improper input validation in some Intel NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.
Affected (13)
Products: Intel: Nuc 8 Home Nuc8i3behfa Firmware, Nuc 8 Home Nuc8i5behfa Firmware, Nuc 8 Home Nuc8i5bekpa Firmware, Nuc 8 Enthusiast Nuc8i7behga Firmware, Nuc 8 Enthusiast Nuc8i7bekqa Firmware, Nuc Kit Nuc8i3beh Firmware, Nuc Kit Nuc8i3bek Firmware, Nuc Kit Nuc8i5beh Firmware, Nuc Kit Nuc8i5bek Firmware, Nuc Kit Nuc8i7beh Firmware, Nuc Kit Nuc8i3behs Firmware, Nuc Kit Nuc8i5behs Firmware, Nuc Kit Nuc8i7bek Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version becfl357.0095 |
| Running on/with | Platform Versions |
|---|---|
Intel Nuc 8 Home Nuc8i3behfa | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version becfl357.0095 |
| Running on/with | Platform Versions |
|---|---|
Intel Nuc 8 Home Nuc8i5behfa | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version becfl357.0095 |
| Running on/with | Platform Versions |
|---|---|
Intel Nuc 8 Home Nuc8i5bekpa | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version becfl357.0095 |
| Running on/with | Platform Versions |
|---|---|
Intel Nuc 8 Enthusiast Nuc8i7behga | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version becfl357.0095 |
| Running on/with | Platform Versions |
|---|---|
Intel Nuc 8 Enthusiast Nuc8i7bekqa | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version becfl357.0095 |
| Running on/with | Platform Versions |
|---|---|
Intel Nuc Kit Nuc8i3beh | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version becfl357.0095 |
| Running on/with | Platform Versions |
|---|---|
Intel Nuc Kit Nuc8i3bek | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Version becfl357.0095 |
| Running on/with | Platform Versions |
|---|---|
Intel Nuc Kit Nuc8i5beh | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Version becfl357.0095 |
| Running on/with | Platform Versions |
|---|---|
Intel Nuc Kit Nuc8i5bek | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Version becfl357.0095 |
| Running on/with | Platform Versions |
|---|---|
Intel Nuc Kit Nuc8i7beh | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Version becfl357.0095 |
| Running on/with | Platform Versions |
|---|---|
Intel Nuc Kit Nuc8i3behs | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Version becfl357.0095 |
| Running on/with | Platform Versions |
|---|---|
Intel Nuc Kit Nuc8i5behs | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Version becfl357.0095 |
| Running on/with | Platform Versions |
|---|---|
Intel Nuc Kit Nuc8i7bek | All versions |
References (2)
Source: secure@intel.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.