CVE-2023-28743

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
19/01/2024
Last modified:
30/01/2024

Description

Improper input validation for some Intel NUC BIOS firmware before version QN0073 may allow a privileged user to potentially enable escalation of privilege via local access.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:intel:nuc_9_pro_compute_element_nuc9v7qnb_firmware:qncflx70.0073:*:*:*:*:*:*:*
cpe:2.3:h:intel:nuc_9_pro_compute_element_nuc9v7qnb:-:*:*:*:*:*:*:*
cpe:2.3:o:intel:nuc_pro_compute_element_nuc9v7qnx_firmware:qncflx70.0073:*:*:*:*:*:*:*
cpe:2.3:h:intel:nuc_9_pro_compute_element_nuc9v7qnx:-:*:*:*:*:*:*:*
cpe:2.3:o:intel:nuc_9_pro_kit_nuc9v7qnb_firmware:qncflx70.0073:*:*:*:*:*:*:*
cpe:2.3:h:intel:nuc_9_pro_kit_nuc9v7qnb:-:*:*:*:*:*:*:*
cpe:2.3:o:intel:nuc_9_pro_kit_nuc9v7qnx_firmware:qncflx70.0073:*:*:*:*:*:*:*
cpe:2.3:h:intel:nuc_9_pro_kit_nuc9v7qnx:-:*:*:*:*:*:*:*