7.8
Advisory Published
Updated

CVE-2022-36789

First published: Fri Nov 11 2022(Updated: )

Improper access control in BIOS firmware for some Intel(R) NUC 10 Performance Kits and Intel(R) NUC 10 Performance Mini PCs before version FNCML357.0053 may allow a privileged user to potentially enable escalation of privilege via local access.

Credit: secure@intel.com

Affected SoftwareAffected VersionHow to fix
Intel NUC 10 Performance Kit NUC10i7FNHN<fncml357.0053
Intel NUC 10 Performance Kit NUC10i7FNHN Firmware
Intel NUC 10 Performance Kit NUC10i5FNKN<fncml357.0053
Intel NUC 10 Performance Kit NUC10i5FNKN
Intel NUC 10 Performance Kit NUC10i5FNH<fncml357.0053
Intel NUC 10 Performance Kit NUC10i5FNHN
Intel NUC 10 Performance Kit NUC10i7FNKN<fncml357.0053
Intel NUC 10 Performance Kit NUC10i7FNKN
Intel NUC 10 Performance Kit NUC10i3FNHN<fncml357.0053
Intel NUC 10 Performance Kit NUC10i3FNHN
Intel NUC 10 Performance Kit NUC10i3FNKN<fncml357.0053
Intel NUC 10 Performance Kit NUC10i3FNKN
Intel NUC 10 Performance Mini PC<fncml357.0053
Intel NUC Performance Kit and Mini PC NUC10i5FNHJA
Intel NUC performance kit and mini PC NUC10i3FNHF firmware<fncml357.0053
Intel NUC 10 Performance Kit NUC10i3FNHF Firmware
Intel NUC Performance Kit and Mini PC NUC10i5FNHCA Firmware<fncml357.0053
Intel NUC Performance Kit and Mini PC NUC10i5FNHCA Firmware
Intel NUC 10 Performance Mini PC NUC10i3FNHFA<fncml357.0053
Intel NUC Performance Kit and Mini PC NUC10i3FNHFA
Intel NUC 10 Performance Kit NUC10i5FNHJ<fncml357.0053
Intel NUC 10 Performance Kit
Intel NUC 10 Performance Kit NUC10i7FNHc Firmware<fncml357.0053
Intel NUC 10 Performance Kit NUC10i7FNHc Firmware
Intel NUC 10 Performance Mini PC NUC10i7FNHJA<fncml357.0053
Intel NUC performance kit and mini pc NUC10i7FNHJA
Intel NUC Performance Kit and Mini PC NUC10i3FNHJA Firmware<fncml357.0053
Intel NUC Performance Kit and Mini PC NUC10i3FNHJA
Intel NUC 10 Performance Kit NUC10i3FNKN<fncml357.0053
Intel NUC Performance Kit NUC10i3FNK
Intel NUC Performance Kit and Mini PC NUC10i7FNHAA Firmware<fncml357.0053
Intel NUC Performance Kit and Mini PC NUC10i7FNHA
Intel NUC 10 Performance Kit NUC10i5FNH<fncml357.0053
Intel NUC 10 Performance Kit
Intel NUC 10 Performance Kit NUC10i5FNKN Firmware<fncml357.0053
Intel NUC performance kit and mini pc NUC10i5FNK
Intel NUC 10 Performance Kit NUC10i7FNHJA Firmware<fncml357.0053
Intel NUC 10 Performance Kit NUC10i7FNH Firmware
Intel NUC 10 performance kit nuc10i5fnhf firmware<fncml357.0053
Intel NUC 10 Performance Kit
Intel NUC 10 Performance Mini PC NUC10i7FNKPA<fncml357.0053
Intel NUC Performance Kit and Mini PC NUC10i7FNKPA
Intel NUC Performance Kit and Mini PC NUC10i5FNKPA Firmware<fncml357.0053
Intel NUC Performance Kit and Mini PC NUC10i5FNKPA
Intel NUC 10 Performance Kit NUC10i3FNHJA Firmware<fncml357.0053
Intel NUC 10 Performance Kit NUC10i3FNHF Firmware
Intel NUC Performance Kit and Mini PC NUC10i7FNK Firmware<fncml357.0053
Intel NUC 10 Performance Kit
Intel NUC 10 Performance Kit NUC10i7FNKPA Firmware<fncml357.0053
Intel NUC Performance Kit and Mini PC NUC10i7FNKP
Intel NUC 10 Performance Kit NUC10i5FNKP<fncml357.0053
Intel NUC 10 Performance Kit (NUC10i5FNKP)

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2022-36789?

    CVE-2022-36789 has a moderate severity level due to improper access control that can allow privilege escalation.

  • How do I fix CVE-2022-36789?

    To fix CVE-2022-36789, update the BIOS firmware to version FNCML357.0053 or later for the affected Intel NUC devices.

  • Which systems are affected by CVE-2022-36789?

    CVE-2022-36789 affects various Intel NUC 10 Performance Kits and Mini PCs with BIOS versions prior to FNCML357.0053.

  • Can CVE-2022-36789 be exploited remotely?

    CVE-2022-36789 primarily requires local access for exploitation, making it less likely to be exploited remotely.

  • Who is impacted by CVE-2022-36789?

    Users of Intel NUC 10 Performance Kits and Mini PCs with the specified vulnerable BIOS versions are impacted by CVE-2022-36789.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203