Nuc Kit Firmware
by Intel
CVEs (15)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-12176 | Hig | 0.53 | 8.2 | 0.00 | Sep 12, 2018 | Improper input validation in firmware for Intel NUC Kits may allow a privileged user to potentially execute arbitrary code resulting in information disclosure, escalation of privilege and/or denial of service via local access. | ||
| CVE-2020-12336 | Hig | 0.51 | 7.8 | 0.00 | Nov 12, 2020 | Insecure default variable initialization in firmware for some Intel(R) NUCs may allow an authenticated user to potentially enable escalation of privilege via local access. | ||
| CVE-2019-11094 | Hig | 0.51 | 7.8 | 0.00 | May 17, 2019 | Insufficient input validation in system firmware for Intel (R) NUC Kit may allow an authenticated user to potentially enable escalation of privilege, denial of service, and/or information disclosure via local access. | ||
| CVE-2020-12337 | Med | 0.44 | 6.7 | 0.00 | Nov 12, 2020 | Improper buffer restrictions in firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access. | ||
| CVE-2019-11140 | Med | 0.44 | 6.7 | 0.00 | Aug 19, 2019 | Insufficient session validation in system firmware for Intel(R) NUC may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access. | ||
| CVE-2019-11129 | Med | 0.44 | 6.7 | 0.00 | Jun 13, 2019 | Out of bound read/write in system firmware for Intel(R) NUC Kit may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access. | ||
| CVE-2019-11128 | Med | 0.44 | 6.7 | 0.00 | Jun 13, 2019 | Insufficient input validation in system firmware for Intel(R) NUC Kit may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access. | ||
| CVE-2019-11127 | Med | 0.44 | 6.7 | 0.00 | Jun 13, 2019 | Buffer overflow in system firmware for Intel(R) NUC Kit may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access. | ||
| CVE-2019-11126 | Med | 0.44 | 6.7 | 0.00 | Jun 13, 2019 | Pointer corruption in system firmware for Intel(R) NUC Kit may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access. | ||
| CVE-2019-11125 | Med | 0.44 | 6.7 | 0.00 | Jun 13, 2019 | Insufficient input validation in system firmware for Intel(R) NUC Kit may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access. | ||
| CVE-2019-11124 | Med | 0.44 | 6.7 | 0.00 | Jun 13, 2019 | Out of bound read/write in system firmware for Intel(R) NUC Kit may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access. | ||
| CVE-2019-11123 | Med | 0.44 | 6.7 | 0.00 | Jun 13, 2019 | Insufficient session validation in system firmware for Intel(R) NUC Kit may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access. | ||
| CVE-2017-3718 | Med | 0.40 | 6.2 | 0.00 | Jan 10, 2019 | Improper setting of device configuration in system firmware for Intel(R) NUC kits may allow a privileged user to potentially enable escalation of privilege via physical access. | ||
| CVE-2018-12158 | Med | 0.39 | 6.0 | 0.00 | Oct 10, 2018 | Insufficient input validation in BIOS update utility in Intel NUC FW kits downloaded before May 24, 2018 may allow a privileged user to potentially trigger a denial of service or information disclosure via local access. | ||
| CVE-2021-33086 | Med | 0.36 | 5.5 | 0.00 | Nov 17, 2021 | Out-of-bounds write in firmware for some Intel(R) NUCs may allow an authenticated user to potentially enable denial of service via local access. |
- risk 0.53cvss 8.2epss 0.00
Improper input validation in firmware for Intel NUC Kits may allow a privileged user to potentially execute arbitrary code resulting in information disclosure, escalation of privilege and/or denial of service via local access.
- risk 0.51cvss 7.8epss 0.00
Insecure default variable initialization in firmware for some Intel(R) NUCs may allow an authenticated user to potentially enable escalation of privilege via local access.
- risk 0.51cvss 7.8epss 0.00
Insufficient input validation in system firmware for Intel (R) NUC Kit may allow an authenticated user to potentially enable escalation of privilege, denial of service, and/or information disclosure via local access.
- risk 0.44cvss 6.7epss 0.00
Improper buffer restrictions in firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access.
- risk 0.44cvss 6.7epss 0.00
Insufficient session validation in system firmware for Intel(R) NUC may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access.
- risk 0.44cvss 6.7epss 0.00
Out of bound read/write in system firmware for Intel(R) NUC Kit may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access.
- risk 0.44cvss 6.7epss 0.00
Insufficient input validation in system firmware for Intel(R) NUC Kit may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access.
- risk 0.44cvss 6.7epss 0.00
Buffer overflow in system firmware for Intel(R) NUC Kit may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access.
- risk 0.44cvss 6.7epss 0.00
Pointer corruption in system firmware for Intel(R) NUC Kit may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access.
- risk 0.44cvss 6.7epss 0.00
Insufficient input validation in system firmware for Intel(R) NUC Kit may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access.
- risk 0.44cvss 6.7epss 0.00
Out of bound read/write in system firmware for Intel(R) NUC Kit may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access.
- risk 0.44cvss 6.7epss 0.00
Insufficient session validation in system firmware for Intel(R) NUC Kit may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access.
- risk 0.40cvss 6.2epss 0.00
Improper setting of device configuration in system firmware for Intel(R) NUC kits may allow a privileged user to potentially enable escalation of privilege via physical access.
- risk 0.39cvss 6.0epss 0.00
Insufficient input validation in BIOS update utility in Intel NUC FW kits downloaded before May 24, 2018 may allow a privileged user to potentially trigger a denial of service or information disclosure via local access.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds write in firmware for some Intel(R) NUCs may allow an authenticated user to potentially enable denial of service via local access.