CVE-2023-38587: Input Validation
Published Jan 19, 2024
·Updated
Improper input validation in some Intel NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.
Affected Software
26 affected components
All of the following
Intel Nuc 8 Home Nuc8i3behfa Firmware=becfl357.0095
Intel Nuc 8 Home Nuc8i3behfa
All of the following
Intel Nuc 8 Home Nuc8i5behfa Firmware=becfl357.0095
Intel Nuc 8 Home Nuc8i5behfa
All of the following
Intel Nuc 8 Home Nuc8i5bekpa Firmware=becfl357.0095
Intel Nuc 8 Home Nuc8i5bekpa
All of the following
Intel Nuc 8 Enthusiast Nuc8i7behga Firmware=becfl357.0095
Intel Nuc 8 Enthusiast Nuc8i7behga
All of the following
Intel Nuc 8 Enthusiast Nuc8i7bekqa Firmware=becfl357.0095
Intel Nuc 8 Enthusiast Nuc8i7bekqa
All of the following
Intel Nuc Kit Nuc8i3beh Firmware=becfl357.0095
Intel Nuc Kit Nuc8i3beh
All of the following
Intel Nuc Kit Nuc8i3bek Firmware=becfl357.0095
Intel Nuc Kit Nuc8i3bek
All of the following
Intel Nuc Kit Nuc8i5beh Firmware=becfl357.0095
Intel Nuc Kit Nuc8i5beh
All of the following
Intel Nuc Kit Nuc8i5bek Firmware=becfl357.0095
Intel Nuc Kit Nuc8i5bek
All of the following
Intel Nuc Kit Nuc8i7beh Firmware=becfl357.0095
Intel Nuc Kit Nuc8i7beh
All of the following
Intel Nuc Kit Nuc8i3behs Firmware=becfl357.0095
Intel Nuc Kit Nuc8i3behs
All of the following
Intel Nuc Kit Nuc8i5behs Firmware=becfl357.0095
Intel Nuc Kit Nuc8i5behs
All of the following
Intel Nuc Kit Nuc8i7bek Firmware=becfl357.0095
Intel Nuc Kit Nuc8i7bek
Event History
Jan 19, 2024
CVE Published
via MITRE·08:03 PM
Data Sourced
via MITRE·08:03 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-38587?
CVE-2023-38587 has a high severity rating due to its potential to allow escalation of privilege via local access.
2
How do I fix CVE-2023-38587?
To fix CVE-2023-38587, it is recommended to update the Intel NUC BIOS firmware to the latest version.
3
Which devices are affected by CVE-2023-38587?
CVE-2023-38587 affects several Intel NUC devices that are operating with the firmware version becfl357.0095.
4
What type of vulnerability is CVE-2023-38587?
CVE-2023-38587 is classified as an improper input validation vulnerability.
5
Who is affected by CVE-2023-38587?
Privileged users with local access to affected Intel NUC devices are at risk due to CVE-2023-38587.