2023-11-20 21:00:21 +00:00

168 lines
5.4 KiB
JSON

{
"id": "CVE-2022-27229",
"sourceIdentifier": "secure@intel.com",
"published": "2023-11-14T19:15:10.813",
"lastModified": "2023-11-20T20:53:38.613",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "Path transversal in some Intel(R) NUC Kits NUC7i3DN, NUC7i5DN, NUC7i7DN HDMI firmware update tool software before version 1.79.1.1 may allow an authenticated user to potentially enable escalation of privilege via local access."
},
{
"lang": "es",
"value": "Path transversal en Intel(R) NUC Kits NUC7i3DN, NUC7i5DN, NUC7i7DN Software de herramienta de actualizaci\u00f3n de firmware HDMI anteriores a la versi\u00f3n 1.79.1.1 puede permitir que un usuario autenticado habilite potencialmente la escalada de privilegios a trav\u00e9s del acceso local."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"attackVector": "LOCAL",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 7.8,
"baseSeverity": "HIGH"
},
"exploitabilityScore": 1.8,
"impactScore": 5.9
},
{
"source": "secure@intel.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H",
"attackVector": "LOCAL",
"attackComplexity": "HIGH",
"privilegesRequired": "LOW",
"userInteraction": "REQUIRED",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 6.7,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 0.8,
"impactScore": 5.9
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-22"
}
]
},
{
"source": "secure@intel.com",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-249"
}
]
}
],
"configurations": [
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:intel:hdmi_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.79.1.1",
"matchCriteriaId": "EF6754EE-BF82-445C-9C8D-88E60039FC8A"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:intel:nuc_7_business_nuc7i3dnhnc:-:*:*:*:*:*:*:*",
"matchCriteriaId": "3204F73F-448F-4D27-91EC-0B51EDA52563"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:intel:nuc_7_business_nuc7i3dnktc:-:*:*:*:*:*:*:*",
"matchCriteriaId": "F5A34B36-9883-4614-AA99-909386365342"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:intel:nuc_7_business_nuc7i5dnkpc:-:*:*:*:*:*:*:*",
"matchCriteriaId": "97BE736A-7802-4DBC-83EF-DA94C32CFFFA"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:intel:nuc_7_business_nuc7i5dnkpu:-:*:*:*:*:*:*:*",
"matchCriteriaId": "7904A205-3072-46AB-88E6-3EBEA1E53BD4"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:intel:nuc_kit_nuc7i3dnhe:-:*:*:*:*:*:*:*",
"matchCriteriaId": "3143ABA5-9741-4CD2-AB9A-A7600EA6E32F"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:intel:nuc_kit_nuc7i3dnke:-:*:*:*:*:*:*:*",
"matchCriteriaId": "97A8937C-5050-436C-B08C-1CA8F1F49FA6"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:intel:nuc_kit_nuc7i5dnhe:-:*:*:*:*:*:*:*",
"matchCriteriaId": "8E845C54-797F-4DAC-87ED-D5FDEDBAC5D6"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:intel:nuc_kit_nuc7i5dnke:-:*:*:*:*:*:*:*",
"matchCriteriaId": "2EF7E820-8567-4E9A-8247-5E1665FFF8BC"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:intel:nuc_kit_nuc7i7dnhe:-:*:*:*:*:*:*:*",
"matchCriteriaId": "550295DC-BA99-4A39-AF81-6109D4955B36"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:intel:nuc_kit_nuc7i7dnke:-:*:*:*:*:*:*:*",
"matchCriteriaId": "5DFDFEB2-B10D-489E-B51C-10FA84E65858"
}
]
}
]
}
],
"references": [
{
"url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00908.html",
"source": "secure@intel.com",
"tags": [
"Patch",
"Vendor Advisory"
]
}
]
}