Core I5 9400f Firmware
by Intel
CVEs (33)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-33123 | Hig | 0.51 | 7.8 | 0.00 | May 12, 2022 | Improper access control in the BIOS authenticated code module for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access. | ||
| CVE-2021-33122 | Hig | 0.51 | 7.8 | 0.00 | May 12, 2022 | Insufficient control flow management in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access. | ||
| CVE-2021-0156 | Hig | 0.51 | 7.8 | 0.00 | Feb 9, 2022 | Improper input validation in the firmware for some Intel(R) Processors may allow an authenticated user to potentially enable an escalation of privilege via local access. | ||
| CVE-2021-0117 | Hig | 0.51 | 7.8 | 0.00 | Feb 9, 2022 | Pointer issues in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access. | ||
| CVE-2021-0116 | Hig | 0.51 | 7.8 | 0.00 | Feb 9, 2022 | Out-of-bounds write in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access. | ||
| CVE-2022-33894 | Hig | 0.49 | 7.5 | 0.00 | May 10, 2023 | Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. | ||
| CVE-2016-1349 | Hig | 0.49 | 7.5 | 0.02 | Mar 26, 2016 | The Smart Install client implementation in Cisco IOS 12.2, 15.0, and 15.2 and IOS XE 3.2 through 3.7 allows remote attackers to cause a denial of service (device reload) via crafted image list parameters in a Smart Install packet, aka Bug ID CSCuv45410. | ||
| CVE-2022-44611 | Med | 0.45 | 6.9 | 0.00 | Aug 11, 2023 | Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via adjacent access. | ||
| CVE-2021-33124 | Med | 0.44 | 6.7 | 0.00 | May 12, 2022 | Out-of-bounds write in the BIOS authenticated code module for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access. | ||
| CVE-2021-33103 | Med | 0.44 | 6.7 | 0.00 | May 12, 2022 | Unintended intermediary in the BIOS authenticated code module for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access. | ||
| CVE-2021-0118 | Med | 0.44 | 6.7 | 0.00 | Feb 9, 2022 | Out-of-bounds read in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access. | ||
| CVE-2019-11157 | Med | 0.44 | 6.7 | 0.01 | Dec 16, 2019 | Improper conditions check in voltage settings for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege and/or information disclosure via local access. | ||
| CVE-2022-40982 | Med | 0.43 | 6.5 | 0.03 | Aug 11, 2023 | Information exposure through microarchitectural state after transient execution in certain vector execution units for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. | ||
| CVE-2021-0125 | Med | 0.43 | 6.6 | 0.00 | Feb 9, 2022 | Improper initialization in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via physical access. | ||
| CVE-2021-0124 | Med | 0.43 | 6.6 | 0.00 | Feb 9, 2022 | Improper access control in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via physical access. | ||
| CVE-2019-11135 | Med | 0.43 | 6.5 | 0.03 | Nov 14, 2019 | TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. | ||
| CVE-2021-0119 | Med | 0.40 | 6.2 | 0.00 | Feb 9, 2022 | Improper initialization in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via physical access. | ||
| CVE-2022-38090 | Med | 0.39 | 6.0 | 0.00 | Feb 16, 2023 | Improper isolation of shared resources in some Intel(R) Processors when using Intel(R) Software Guard Extensions may allow a privileged user to potentially enable information disclosure via local access. | ||
| CVE-2022-26373 | Med | 0.36 | 5.5 | 0.00 | Aug 18, 2022 | Non-transparent sharing of return predictor targets between contexts in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access. | ||
| CVE-2022-21180 | Med | 0.36 | 5.5 | 0.00 | Jun 15, 2022 | Improper input validation for some Intel(R) Processors may allow an authenticated user to potentially cause a denial of service via local access. |
- risk 0.51cvss 7.8epss 0.00
Improper access control in the BIOS authenticated code module for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.
- risk 0.51cvss 7.8epss 0.00
Insufficient control flow management in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.
- risk 0.51cvss 7.8epss 0.00
Improper input validation in the firmware for some Intel(R) Processors may allow an authenticated user to potentially enable an escalation of privilege via local access.
- risk 0.51cvss 7.8epss 0.00
Pointer issues in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access.
- risk 0.51cvss 7.8epss 0.00
Out-of-bounds write in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access.
- risk 0.49cvss 7.5epss 0.00
Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
- risk 0.49cvss 7.5epss 0.02
The Smart Install client implementation in Cisco IOS 12.2, 15.0, and 15.2 and IOS XE 3.2 through 3.7 allows remote attackers to cause a denial of service (device reload) via crafted image list parameters in a Smart Install packet, aka Bug ID CSCuv45410.
- risk 0.45cvss 6.9epss 0.00
Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via adjacent access.
- risk 0.44cvss 6.7epss 0.00
Out-of-bounds write in the BIOS authenticated code module for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.
- risk 0.44cvss 6.7epss 0.00
Unintended intermediary in the BIOS authenticated code module for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.
- risk 0.44cvss 6.7epss 0.00
Out-of-bounds read in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access.
- risk 0.44cvss 6.7epss 0.01
Improper conditions check in voltage settings for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege and/or information disclosure via local access.
- risk 0.43cvss 6.5epss 0.03
Information exposure through microarchitectural state after transient execution in certain vector execution units for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
- risk 0.43cvss 6.6epss 0.00
Improper initialization in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via physical access.
- risk 0.43cvss 6.6epss 0.00
Improper access control in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via physical access.
- risk 0.43cvss 6.5epss 0.03
TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.
- risk 0.40cvss 6.2epss 0.00
Improper initialization in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via physical access.
- risk 0.39cvss 6.0epss 0.00
Improper isolation of shared resources in some Intel(R) Processors when using Intel(R) Software Guard Extensions may allow a privileged user to potentially enable information disclosure via local access.
- risk 0.36cvss 5.5epss 0.00
Non-transparent sharing of return predictor targets between contexts in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.
- risk 0.36cvss 5.5epss 0.00
Improper input validation for some Intel(R) Processors may allow an authenticated user to potentially cause a denial of service via local access.
Page 1 of 2