CVE-2023-40220: Medium severity intel nuc kit nuc6cayh firmware vulnerability
Published Nov 14, 2023
·Updated
Improper buffer restrictions in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable information disclosure via local access.
Affected Software
4 affected components
Intel Nuc6cayh Firmware<ayaplcel.86a.0076
Intel Nuc6cayh
Intel Nuc6cays Firmware<ayaplcel.86a.0076
Intel Nuc6cays
Event History
Nov 14, 2023
CVE Published
07:05 PM
Data Sourced
07:05 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2023-40220.
2
What is the title of this vulnerability?
The title of this vulnerability is 'Improper buffer restrictions in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable information disclosure via local access.'
3
What is the severity of CVE-2023-40220?
The severity of CVE-2023-40220 is medium, with a severity value of 5.3.
4
What software is affected by this vulnerability?
The Intel Nuc6cayh Firmware and Intel Nuc6cays Firmware versions up to exclusive ayaplcel.86a.0076 are affected.
5
How do I fix CVE-2023-40220?
To fix CVE-2023-40220, update the Intel NUC BIOS firmware to a version that includes the necessary fixes.