CVE-2022-38099: Input Validation
Published Nov 11, 2022
·Updated
Improper input validation in BIOS firmware for some Intel(R) NUC 11 Compute Elements before version EBTGL357.0065 may allow a privileged user to potentially enable escalation of privilege via local access.
Affected Software
16 affected components
Intel NUC 11 Compute Element<ebtgl357.0065
Intel NUC 11 Compute Element
Intel CM11EBC4W Firmware<ebtgl357.0065
Intel NUC 11 Compute Element CM11EBC4W Firmware
Intel NUC 11 Compute Element CM11EBI58W<ebtgl357.0065
Intel Compute Module CM11EBI58W
Intel NUC 11 Compute Element<ebtgl357.0065
Intel NUC 11 Compute Element cm11ebv58w firmware
Intel cm11ebi716w firmware<ebtgl357.0065
Intel NUC 11 Compute Element
Intel NUC 11 Compute Element<ebtgl357.0065
Intel NUC 11 Compute Element
Intel NUC 11 NUC11DBBi9 Firmware<ebtgl357.0065
Intel NUC 11 NUC11DBBi9 Firmware
Intel NUC 11 DBBI7 Firmware<ebtgl357.0065
Intel NUC 11 DBBI7 Firmware
Event History
Nov 11, 2022
CVE Published
via MITRE·03:48 PM
Data Sourced
via MITRE·03:48 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2022-38099.
2
What is the severity of CVE-2022-38099?
The severity of CVE-2022-38099 is high with a severity value of 7.8.
3
Which software versions are affected by CVE-2022-38099?
BIOS firmware for some Intel(R) NUC 11 Compute Elements before version EBTGL357.0065 are affected by CVE-2022-38099.
4
How can a privileged user potentially exploit this vulnerability?
A privileged user can potentially enable escalation of privilege via local access using this vulnerability.
5
Where can I find more information about CVE-2022-38099?
You can find more information about CVE-2022-38099 on the Intel Security Center Advisory page: [Intel SA-00752](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00752.html).