CVE-2022-21933
Severity CVSS v4.0:
Pending analysis
Type:
CWE-787
Out-of-bounds Write
Publication date:
21/01/2022
Last modified:
24/07/2023
Description
ASUS VivoMini/Mini PC device has an improper input validation vulnerability. A local attacker with system privilege can use system management interrupt (SMI) to modify memory, resulting in arbitrary code execution for controlling the system or disrupting service.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Base Score 2.0
7.20
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:asus:vc65-c1_firmware:*:*:*:*:*:*:*:* | 1302 (excluding) | |
| cpe:2.3:h:asus:vc65-c1:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:asus:pb60v_firmware:*:*:*:*:*:*:*:* | 1302 (excluding) | |
| cpe:2.3:h:asus:pb60v:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:asus:pb60g_firmware:*:*:*:*:*:*:*:* | 1302 (excluding) | |
| cpe:2.3:h:asus:pb60g:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:asus:pb60s_firmware:*:*:*:*:*:*:*:* | 1302 (excluding) | |
| cpe:2.3:h:asus:pb60s:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:asus:pa90_firmware:*:*:*:*:*:*:*:* | 1401 (excluding) | |
| cpe:2.3:h:asus:pa90:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:asus:pb50_firmware:*:*:*:*:*:*:*:* | 902 (excluding) | |
| cpe:2.3:h:asus:pb50:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:asus:pb60_firmware:*:*:*:*:*:*:*:* | 1502 (excluding) | |
| cpe:2.3:h:asus:pb60:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:asus:pb61v_firmware:*:*:*:*:*:*:*:* | 601 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



