CVE-2023-28743

Improper input validation for some Intel NUC BIOS firmware before version QN0073 may allow a privileged user to potentially enable escalation of privilege via local access.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:intel:nuc_9_pro_compute_element_nuc9v7qnb_firmware:qncflx70.0073:*:*:*:*:*:*:*
cpe:2.3:h:intel:nuc_9_pro_compute_element_nuc9v7qnb:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:intel:nuc_pro_compute_element_nuc9v7qnx_firmware:qncflx70.0073:*:*:*:*:*:*:*
cpe:2.3:h:intel:nuc_9_pro_compute_element_nuc9v7qnx:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:intel:nuc_9_pro_kit_nuc9v7qnb_firmware:qncflx70.0073:*:*:*:*:*:*:*
cpe:2.3:h:intel:nuc_9_pro_kit_nuc9v7qnb:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:intel:nuc_9_pro_kit_nuc9v7qnx_firmware:qncflx70.0073:*:*:*:*:*:*:*
cpe:2.3:h:intel:nuc_9_pro_kit_nuc9v7qnx:-:*:*:*:*:*:*:*

History

30 Jan 2024, 15:17

Type Values Removed Values Added
CPE cpe:2.3:h:intel:nuc_9_pro_kit_nuc9v7qnb:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:nuc_9_pro_kit_nuc9v7qnx:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:nuc_9_pro_compute_element_nuc9v7qnb:-:*:*:*:*:*:*:*
cpe:2.3:o:intel:nuc_pro_compute_element_nuc9v7qnx_firmware:qncflx70.0073:*:*:*:*:*:*:*
cpe:2.3:h:intel:nuc_9_pro_compute_element_nuc9v7qnx:-:*:*:*:*:*:*:*
cpe:2.3:o:intel:nuc_9_pro_compute_element_nuc9v7qnb_firmware:qncflx70.0073:*:*:*:*:*:*:*
cpe:2.3:o:intel:nuc_9_pro_kit_nuc9v7qnb_firmware:qncflx70.0073:*:*:*:*:*:*:*
cpe:2.3:o:intel:nuc_9_pro_kit_nuc9v7qnx_firmware:qncflx70.0073:*:*:*:*:*:*:*
First Time Intel nuc 9 Pro Compute Element Nuc9v7qnb
Intel nuc 9 Pro Kit Nuc9v7qnx
Intel nuc 9 Pro Compute Element Nuc9v7qnx
Intel nuc 9 Pro Compute Element Nuc9v7qnb Firmware
Intel nuc Pro Compute Element Nuc9v7qnx Firmware
Intel nuc 9 Pro Kit Nuc9v7qnx Firmware
Intel
Intel nuc 9 Pro Kit Nuc9v7qnb
Intel nuc 9 Pro Kit Nuc9v7qnb Firmware
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 7.8
References () https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01009.html - () https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01009.html - Vendor Advisory
Summary
  • (es) La validación de entrada incorrecta para algunos firmware de BIOS Intel NUC anteriores a la versión QN0073 puede permitir que un usuario privilegiado habilite potencialmente la escalada de privilegios a través del acceso local.

19 Jan 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-19 20:15

Updated : 2024-01-30 15:17


NVD link : CVE-2023-28743

Mitre link : CVE-2023-28743

CVE.ORG link : CVE-2023-28743


JSON object : View

Products Affected

intel

  • nuc_9_pro_kit_nuc9v7qnb
  • nuc_9_pro_kit_nuc9v7qnb_firmware
  • nuc_9_pro_compute_element_nuc9v7qnx
  • nuc_9_pro_compute_element_nuc9v7qnb
  • nuc_9_pro_kit_nuc9v7qnx
  • nuc_9_pro_compute_element_nuc9v7qnb_firmware
  • nuc_pro_compute_element_nuc9v7qnx_firmware
  • nuc_9_pro_kit_nuc9v7qnx_firmware
CWE
CWE-20

Improper Input Validation