VYPR

NUC Kits

by Intel

CVEs (8)

  • CVE-2018-12176HigSep 12, 2018
    risk 0.53cvss 8.2epss 0.00

    Improper input validation in firmware for Intel NUC Kits may allow a privileged user to potentially execute arbitrary code resulting in information disclosure, escalation of privilege and/or denial of service via local access.

  • CVE-2022-37345HigNov 11, 2022
    risk 0.51cvss 7.8epss 0.00

    Improper authentication in BIOS firmware[A1] for some Intel(R) NUC Kits before version RY0386 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2018-3612HigMay 10, 2018
    risk 0.51cvss 7.8epss 0.00

    Intel NUC kits with insufficient input validation in system firmware, potentially allows a local attacker to elevate privileges to System Management Mode (SMM).

  • CVE-2022-34152HigNov 11, 2022
    risk 0.50cvss 7.7epss 0.00

    Improper input validation in BIOS firmware for some Intel(R) NUC Boards, Intel(R) NUC Kits before version TY0070 may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2016-8103MedDec 8, 2016
    risk 0.44cvss 6.7epss 0.00

    SMM call out in all Intel Branded NUC Kits allows a local privileged user to access the System Management Mode and take full control of the platform.

  • CVE-2017-3718MedJan 10, 2019
    risk 0.40cvss 6.2epss 0.00

    Improper setting of device configuration in system firmware for Intel(R) NUC kits may allow a privileged user to potentially enable escalation of privilege via physical access.

  • CVE-2018-12158MedOct 10, 2018
    risk 0.39cvss 6.0epss 0.00

    Insufficient input validation in BIOS update utility in Intel NUC FW kits downloaded before May 24, 2018 may allow a privileged user to potentially trigger a denial of service or information disclosure via local access.

  • CVE-2022-32577LowMay 10, 2023
    risk 0.22cvss 3.4epss 0.00

    Improper input validation in BIOS Firmware for some Intel(R) NUC Kits before version PY0081 may allow a privileged user to potentially enable information disclosure or denial of service via local access