CVE-2023-38587

Improper input validation in some Intel NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:intel:nuc_8_home_nuc8i3behfa_firmware:becfl357.0095:*:*:*:*:*:*:*
cpe:2.3:h:intel:nuc_8_home_nuc8i3behfa:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:intel:nuc_8_home_nuc8i5behfa_firmware:becfl357.0095:*:*:*:*:*:*:*
cpe:2.3:h:intel:nuc_8_home_nuc8i5behfa:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:intel:nuc_8_home_nuc8i5bekpa_firmware:becfl357.0095:*:*:*:*:*:*:*
cpe:2.3:h:intel:nuc_8_home_nuc8i5bekpa:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:intel:nuc_8_enthusiast_nuc8i7behga_firmware:becfl357.0095:*:*:*:*:*:*:*
cpe:2.3:h:intel:nuc_8_enthusiast_nuc8i7behga:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:intel:nuc_8_enthusiast_nuc8i7bekqa_firmware:becfl357.0095:*:*:*:*:*:*:*
cpe:2.3:h:intel:nuc_8_enthusiast_nuc8i7bekqa:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:intel:nuc_kit_nuc8i3beh_firmware:becfl357.0095:*:*:*:*:*:*:*
cpe:2.3:h:intel:nuc_kit_nuc8i3beh:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:intel:nuc_kit_nuc8i3bek_firmware:becfl357.0095:*:*:*:*:*:*:*
cpe:2.3:h:intel:nuc_kit_nuc8i3bek:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:intel:nuc_kit_nuc8i5beh_firmware:becfl357.0095:*:*:*:*:*:*:*
cpe:2.3:h:intel:nuc_kit_nuc8i5beh:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:intel:nuc_kit_nuc8i5bek_firmware:becfl357.0095:*:*:*:*:*:*:*
cpe:2.3:h:intel:nuc_kit_nuc8i5bek:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:intel:nuc_kit_nuc8i7beh_firmware:becfl357.0095:*:*:*:*:*:*:*
cpe:2.3:h:intel:nuc_kit_nuc8i7beh:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:intel:nuc_kit_nuc8i3behs_firmware:becfl357.0095:*:*:*:*:*:*:*
cpe:2.3:h:intel:nuc_kit_nuc8i3behs:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:intel:nuc_kit_nuc8i5behs_firmware:becfl357.0095:*:*:*:*:*:*:*
cpe:2.3:h:intel:nuc_kit_nuc8i5behs:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:intel:nuc_kit_nuc8i7bek_firmware:becfl357.0095:*:*:*:*:*:*:*
cpe:2.3:h:intel:nuc_kit_nuc8i7bek:-:*:*:*:*:*:*:*

History

30 Jan 2024, 14:28

Type Values Removed Values Added
CPE cpe:2.3:o:intel:nuc_kit_nuc8i3bek_firmware:becfl357.0095:*:*:*:*:*:*:*
cpe:2.3:o:intel:nuc_kit_nuc8i7beh_firmware:becfl357.0095:*:*:*:*:*:*:*
cpe:2.3:h:intel:nuc_8_home_nuc8i5bekpa:-:*:*:*:*:*:*:*
cpe:2.3:o:intel:nuc_kit_nuc8i5behs_firmware:becfl357.0095:*:*:*:*:*:*:*
cpe:2.3:h:intel:nuc_8_home_nuc8i3behfa:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:nuc_8_home_nuc8i5behfa:-:*:*:*:*:*:*:*
cpe:2.3:o:intel:nuc_8_home_nuc8i5behfa_firmware:becfl357.0095:*:*:*:*:*:*:*
cpe:2.3:o:intel:nuc_8_home_nuc8i3behfa_firmware:becfl357.0095:*:*:*:*:*:*:*
cpe:2.3:h:intel:nuc_kit_nuc8i3bek:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:nuc_kit_nuc8i5bek:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:nuc_kit_nuc8i7bek:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:nuc_kit_nuc8i3behs:-:*:*:*:*:*:*:*
cpe:2.3:o:intel:nuc_8_enthusiast_nuc8i7bekqa_firmware:becfl357.0095:*:*:*:*:*:*:*
cpe:2.3:h:intel:nuc_8_enthusiast_nuc8i7behga:-:*:*:*:*:*:*:*
cpe:2.3:o:intel:nuc_8_enthusiast_nuc8i7behga_firmware:becfl357.0095:*:*:*:*:*:*:*
cpe:2.3:h:intel:nuc_kit_nuc8i5behs:-:*:*:*:*:*:*:*
cpe:2.3:o:intel:nuc_kit_nuc8i3beh_firmware:becfl357.0095:*:*:*:*:*:*:*
cpe:2.3:o:intel:nuc_kit_nuc8i5bek_firmware:becfl357.0095:*:*:*:*:*:*:*
cpe:2.3:h:intel:nuc_kit_nuc8i7beh:-:*:*:*:*:*:*:*
cpe:2.3:o:intel:nuc_kit_nuc8i5beh_firmware:becfl357.0095:*:*:*:*:*:*:*
cpe:2.3:o:intel:nuc_kit_nuc8i3behs_firmware:becfl357.0095:*:*:*:*:*:*:*
cpe:2.3:h:intel:nuc_8_enthusiast_nuc8i7bekqa:-:*:*:*:*:*:*:*
cpe:2.3:o:intel:nuc_8_home_nuc8i5bekpa_firmware:becfl357.0095:*:*:*:*:*:*:*
cpe:2.3:o:intel:nuc_kit_nuc8i7bek_firmware:becfl357.0095:*:*:*:*:*:*:*
cpe:2.3:h:intel:nuc_kit_nuc8i5beh:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:nuc_kit_nuc8i3beh:-:*:*:*:*:*:*:*
First Time Intel nuc Kit Nuc8i5behs
Intel nuc Kit Nuc8i3bek
Intel nuc 8 Enthusiast Nuc8i7bekqa Firmware
Intel nuc 8 Home Nuc8i5behfa Firmware
Intel nuc 8 Enthusiast Nuc8i7behga Firmware
Intel
Intel nuc Kit Nuc8i7beh Firmware
Intel nuc Kit Nuc8i3behs Firmware
Intel nuc 8 Home Nuc8i3behfa Firmware
Intel nuc Kit Nuc8i3beh Firmware
Intel nuc 8 Home Nuc8i5bekpa Firmware
Intel nuc 8 Home Nuc8i5behfa
Intel nuc 8 Enthusiast Nuc8i7behga
Intel nuc Kit Nuc8i3behs
Intel nuc Kit Nuc8i7bek Firmware
Intel nuc 8 Home Nuc8i3behfa
Intel nuc 8 Home Nuc8i5bekpa
Intel nuc Kit Nuc8i5bek
Intel nuc Kit Nuc8i3bek Firmware
Intel nuc Kit Nuc8i7bek
Intel nuc Kit Nuc8i5beh
Intel nuc Kit Nuc8i7beh
Intel nuc Kit Nuc8i5bek Firmware
Intel nuc Kit Nuc8i5beh Firmware
Intel nuc Kit Nuc8i5behs Firmware
Intel nuc Kit Nuc8i3beh
Intel nuc 8 Enthusiast Nuc8i7bekqa
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 7.8
Summary
  • (es) La validación de entrada incorrecta en algunos firmware de BIOS Intel NUC puede permitir que un usuario privilegiado habilite potencialmente la escalada de privilegios a través del acceso local.
References () https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01028.html - () https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01028.html - Vendor Advisory

19 Jan 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-19 20:15

Updated : 2024-01-30 14:28


NVD link : CVE-2023-38587

Mitre link : CVE-2023-38587

CVE.ORG link : CVE-2023-38587


JSON object : View

Products Affected

intel

  • nuc_8_home_nuc8i5behfa
  • nuc_8_enthusiast_nuc8i7bekqa_firmware
  • nuc_8_home_nuc8i3behfa_firmware
  • nuc_8_home_nuc8i5bekpa
  • nuc_kit_nuc8i5beh
  • nuc_kit_nuc8i3beh
  • nuc_kit_nuc8i7beh
  • nuc_8_enthusiast_nuc8i7behga_firmware
  • nuc_kit_nuc8i3behs_firmware
  • nuc_kit_nuc8i5behs_firmware
  • nuc_kit_nuc8i5behs
  • nuc_8_home_nuc8i5behfa_firmware
  • nuc_8_home_nuc8i5bekpa_firmware
  • nuc_kit_nuc8i7bek_firmware
  • nuc_kit_nuc8i7bek
  • nuc_kit_nuc8i5bek_firmware
  • nuc_kit_nuc8i5bek
  • nuc_kit_nuc8i3bek
  • nuc_8_enthusiast_nuc8i7behga
  • nuc_kit_nuc8i7beh_firmware
  • nuc_kit_nuc8i3behs
  • nuc_kit_nuc8i3beh_firmware
  • nuc_8_enthusiast_nuc8i7bekqa
  • nuc_kit_nuc8i5beh_firmware
  • nuc_8_home_nuc8i3behfa
  • nuc_kit_nuc8i3bek_firmware
CWE
CWE-20

Improper Input Validation