CVE-2022-21794: High severity intel nuc8i7hnk firmware vulnerability
Improper authentication in BIOS firmware for some Intel(R) NUC Boards, Intel(R) NUC Business, Intel(R) NUC Enthusiast, Intel(R) NUC Kits before version HN0067 may allow a privileged user to potentially enable escalation of privilege via local access.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-21794?
CVE-2022-21794 is a vulnerability that allows a privileged user to potentially enable escalation of privilege via local access in some Intel NUC Boards, Intel NUC Business, Intel NUC Enthusiast, and Intel NUC Kits before version HN0067.
How can a privileged user exploit CVE-2022-21794?
A privileged user can exploit CVE-2022-21794 through local access to gain escalated privileges.
What is the severity of CVE-2022-21794?
The severity of CVE-2022-21794 is high with a severity score of 6.7.
Which Intel NUC products are affected by CVE-2022-21794?
Intel NUC Kits NUC8i7HNK and NUC8i7HVK, as well as Intel NUC 8 Enthusiast NUC8i7HVKVA and Intel NUC 8 Business NUC8i7HNKQC are affected by CVE-2022-21794.
How do I fix CVE-2022-21794?
To mitigate CVE-2022-21794, it is recommended to update the BIOS firmware of the affected Intel NUC Boards and Kits to version HN0067 or later.