CVE-2023-28743: Input Validation
Published Jan 19, 2024
·Updated
Improper input validation for some Intel NUC BIOS firmware before version QN0073 may allow a privileged user to potentially enable escalation of privilege via local access.
Affected Software
8 affected components
All of the following
Intel Nuc 9 Pro Compute Element Nuc9v7qnb Firmware=qncflx70.0073
Intel Nuc 9 Pro Compute Element Nuc9v7qnb
All of the following
Intel Nuc Pro Compute Element Nuc9v7qnx Firmware=qncflx70.0073
Intel Nuc 9 Pro Compute Element Nuc9v7qnx
All of the following
Intel Nuc 9 Pro Kit Nuc9v7qnb Firmware=qncflx70.0073
Intel Nuc 9 Pro Kit Nuc9v7qnb
All of the following
Intel Nuc 9 Pro Kit Nuc9v7qnx Firmware=qncflx70.0073
Intel Nuc 9 Pro Kit Nuc9v7qnx
Event History
Jan 19, 2024
CVE Published
via MITRE·08:03 PM
Data Sourced
via MITRE·08:03 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-28743?
CVE-2023-28743 has a severity rating that indicates a potential escalation of privilege risk for users with local access.
2
How do I fix CVE-2023-28743?
To fix CVE-2023-28743, update your Intel NUC BIOS firmware to version QN0073 or later.
3
Who is affected by CVE-2023-28743?
CVE-2023-28743 affects users of Intel NUC 9 Pro Compute Element and Intel NUC 9 Pro Kit devices running BIOS firmware versions prior to QN0073.
4
What type of vulnerability is CVE-2023-28743?
CVE-2023-28743 is an improper input validation vulnerability that can lead to privilege escalation.
5
Can CVE-2023-28743 be exploited remotely?
CVE-2023-28743 requires local access for exploitation, making it less of a risk for remote attacks.