CVE-2022-36370: High severity intel nuc5i3myhe firmware vulnerability
Published Nov 11, 2022
·Updated
Improper authentication in BIOS firmware for some Intel(R) NUC Boards and Intel(R) NUC Kits before version MYi30060 may allow a privileged user to potentially enable escalation of privilege via local access.
Affected Software
8 affected components
All of the following
Intel Nuc Kit Nuc5i3myhe Firmware<myi30060
Intel Nuc Kit Nuc5i3myhe
All of the following
Intel Nuc Board Nuc5i3mybe Firmware<myi30060
Intel Nuc Board Nuc5i3mybe
Intel Nuc Kit Nuc5i3myhe Firmware<myi30060
Intel Nuc Kit Nuc5i3myhe
Intel Nuc Board Nuc5i3mybe Firmware<myi30060
Intel Nuc Board Nuc5i3mybe
Remediation
Event History
Nov 11, 2022
CVE Published
via MITRE·03:48 PM
Data Sourced
via MITRE·03:48 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this security advisory?
The vulnerability ID for this security advisory is CVE-2022-36370.
2
What is the severity of CVE-2022-36370?
The severity of CVE-2022-36370 is 7.8 (High).
3
Which Intel NUC Boards and Kits are affected by CVE-2022-36370?
The Intel NUC Boards and Kits affected by CVE-2022-36370 are NUC5i3MYHE and NUC5i3MYBE.
4
What is the potential impact of CVE-2022-36370?
The potential impact of CVE-2022-36370 is that a privileged user may be able to enable escalation of privilege via local access.
5
How can I fix the CVE-2022-36370 vulnerability?
To fix the CVE-2022-36370 vulnerability, you should update the BIOS firmware for the affected Intel NUC Boards and Kits to version MYi30060 or later.