CVE-2022-21933

ASUS VivoMini/Mini PC device has an improper input validation vulnerability. A local attacker with system privilege can use system management interrupt (SMI) to modify memory, resulting in arbitrary code execution for controlling the system or disrupting service.
References
Link Resource
https://www.twcert.org.tw/tw/cp-132-5547-34bc4-1.html Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:asus:vc65-c1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asus:vc65-c1:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:asus:pb60v_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asus:pb60v:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:asus:pb60g_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asus:pb60g:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:asus:pb60s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asus:pb60s:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:asus:pa90_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asus:pa90:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:asus:pb50_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asus:pb50:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:asus:pb60_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asus:pb60:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:asus:pb61v_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asus:pb61v:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:asus:ts10_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asus:ts10:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:asus:pn40_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asus:pn40:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:asus:pn60_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asus:pn60:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:asus:pn30_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asus:pn30:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:asus:un65u_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asus:un65u:-:*:*:*:*:*:*:*

History

24 Jul 2023, 13:53

Type Values Removed Values Added
CWE CWE-20 CWE-787

27 Jan 2022, 16:30

Type Values Removed Values Added
References (CONFIRM) https://www.twcert.org.tw/tw/cp-132-5547-34bc4-1.html - (CONFIRM) https://www.twcert.org.tw/tw/cp-132-5547-34bc4-1.html - Third Party Advisory
First Time Asus pb61v
Asus pb60s Firmware
Asus un65u Firmware
Asus pn30
Asus pa90 Firmware
Asus pb60g
Asus pb60
Asus pb50
Asus pb50 Firmware
Asus pn40 Firmware
Asus vc65-c1
Asus un65u
Asus ts10
Asus pn30 Firmware
Asus pb60 Firmware
Asus
Asus pb60v Firmware
Asus pn40
Asus pb60v
Asus pb60s
Asus ts10 Firmware
Asus pb60g Firmware
Asus vc65-c1 Firmware
Asus pn60 Firmware
Asus pb61v Firmware
Asus pn60
Asus pa90
CWE CWE-20
CVSS v2 : unknown
v3 : unknown
v2 : 7.2
v3 : 7.8
CPE cpe:2.3:h:asus:pb60g:-:*:*:*:*:*:*:*
cpe:2.3:o:asus:pn40_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:asus:pn30_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:asus:ts10_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asus:pa90:-:*:*:*:*:*:*:*
cpe:2.3:h:asus:ts10:-:*:*:*:*:*:*:*
cpe:2.3:h:asus:pb60:-:*:*:*:*:*:*:*
cpe:2.3:o:asus:pa90_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asus:pb50:-:*:*:*:*:*:*:*
cpe:2.3:o:asus:pb60g_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:asus:pb60_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asus:un65u:-:*:*:*:*:*:*:*
cpe:2.3:o:asus:un65u_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:asus:vc65-c1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asus:pb60v:-:*:*:*:*:*:*:*
cpe:2.3:o:asus:pn60_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:asus:pb60v_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asus:vc65-c1:-:*:*:*:*:*:*:*
cpe:2.3:h:asus:pb61v:-:*:*:*:*:*:*:*
cpe:2.3:o:asus:pb60s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:asus:pb50_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asus:pn40:-:*:*:*:*:*:*:*
cpe:2.3:h:asus:pn30:-:*:*:*:*:*:*:*
cpe:2.3:h:asus:pb60s:-:*:*:*:*:*:*:*
cpe:2.3:h:asus:pn60:-:*:*:*:*:*:*:*
cpe:2.3:o:asus:pb61v_firmware:*:*:*:*:*:*:*:*

21 Jan 2022, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-01-21 09:15

Updated : 2023-12-10 14:09


NVD link : CVE-2022-21933

Mitre link : CVE-2022-21933

CVE.ORG link : CVE-2022-21933


JSON object : View

Products Affected

asus

  • pn40_firmware
  • pb60g_firmware
  • pn60_firmware
  • pb61v_firmware
  • un65u_firmware
  • pn40
  • pb60v
  • ts10_firmware
  • vc65-c1
  • pa90
  • pn30
  • pn60
  • pb60_firmware
  • pn30_firmware
  • un65u
  • pb60
  • pb60s
  • pb50
  • pb60v_firmware
  • pb50_firmware
  • pb60s_firmware
  • vc65-c1_firmware
  • pa90_firmware
  • ts10
  • pb61v
  • pb60g
CWE
CWE-787

Out-of-bounds Write

CWE-20

Improper Input Validation