CVE-2022-36339: Input Validation
Published May 10, 2023
·Updated
Improper input validation in firmware for Intel(R) NUC 8 Compute Element, Intel(R) NUC 11 Compute Element, Intel(R) NUC 12 Compute Element may allow a privileged user to enable escalation of privilege via local access.
Affected Software
26 affected components
Intel CM8I3CB4N<cbwhl357.0101
Intel CM8I3CB4N Firmware
Intel NUC8i5BEK Firmware<cbwhl357.0101
Intel NUC 8i5BEH
Intel CM8I7CB8N Firmware<cbwhl357.0101
Intel NUC 8i7 Behga
Intel CM8CCB4R Firmware<cbwhl357.0101
Intel CM8CCB4R Firmware
Intel CM8PCB4R<cbwhl357.0101
Intel NUC 8 Compute Element CM8PCB4R
Intel CM11EBI38W<ebtgl357.0071
Intel Compute Module CM11EBI38W
Intel CM11EBI58W<ebtgl357.0071
Intel Compute Module CM11EBI58W
Intel CM11EBI716W Firmware<ebtgl357.0071
Intel cm11ebi716w firmware
Intel CM11EBC4W Firmware<ebtgl357.0071
Intel cm11ebc4w firmware
Intel NUC 12 Compute Element ELM12HBI3 Firmware<hbadl357.0052
Intel ELM12HBI3 Firmware
Intel Elm12HBI5<hbadl357.0052
Intel Elm12HBI5
Intel ELM12HBI7 Firmware<hbadl357.0052
Intel ELM12HBI7 Firmware
Intel ELM12HBC<hbadl357.0052
Intel NUC 12 Compute Element ELM12HBC
Event History
May 10, 2023
CVE Published
via MITRE·01:16 PM
Data Sourced
via MITRE·01:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-36339.
2
What is the severity of CVE-2022-36339?
The severity of CVE-2022-36339 is high.
3
Which software is affected by CVE-2022-36339?
Intel(R) NUC 8 Compute Element, Intel(R) NUC 11 Compute Element, and Intel(R) NUC 12 Compute Element firmware versions cbwhl357.0101 and earlier are affected by CVE-2022-36339.
4
How does CVE-2022-36339 enable escalation of privilege?
CVE-2022-36339 allows a privileged user to enable escalation of privilege via local access.
5
How can I fix CVE-2022-36339?
To fix CVE-2022-36339, update the firmware of your Intel NUC 8, NUC 11, or NUC 12 Compute Element to a version later than cbwhl357.0101.