CVE-2022-26343

MEDIUMCVSS 6.7/10EPSS 0.25%

Last modified

CVE-2022-26343 is a medium-severity vulnerability rated 6.7/10 on the CVSS scale. Improper access control in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.. EPSS estimates a 0.25% chance of exploitation in the next 30 days.

Description

Improper access control in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

Metrics

CVSS 3.1
6.7/10

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.25%

16.1th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
IntelXeon Bronze 3104 FirmwareAll versions
IntelXeon Bronze 3106 FirmwareAll versions
IntelXeon Bronze 3204 FirmwareAll versions
IntelXeon Bronze 3206r FirmwareAll versions
IntelXeon D-1513n FirmwareAll versions
IntelXeon D-1518 FirmwareAll versions
IntelXeon D-1520 FirmwareAll versions
IntelXeon D-1521 FirmwareAll versions
IntelXeon D-1523n FirmwareAll versions
IntelXeon D-1527 FirmwareAll versions
IntelXeon D-1528 FirmwareAll versions
IntelXeon D-1529 FirmwareAll versions
IntelXeon D-1531 FirmwareAll versions
IntelXeon D-1533n FirmwareAll versions
IntelXeon D-1537 FirmwareAll versions
IntelXeon D-1539 FirmwareAll versions
IntelXeon D-1540 FirmwareAll versions
IntelXeon D-1541 FirmwareAll versions
IntelXeon D-1543n FirmwareAll versions
IntelXeon D-1548 FirmwareAll versions
IntelXeon D-1553n FirmwareAll versions
IntelXeon D-1557 FirmwareAll versions
IntelXeon D-1559 FirmwareAll versions
IntelXeon D-1567 FirmwareAll versions
IntelXeon D-1571 FirmwareAll versions
IntelXeon D-1577 FirmwareAll versions
IntelXeon D-1602 FirmwareAll versions
IntelXeon D-1622 FirmwareAll versions
IntelXeon D-1623n FirmwareAll versions
IntelXeon D-1627 FirmwareAll versions
IntelXeon D-1633n FirmwareAll versions
IntelXeon D-1637 FirmwareAll versions
IntelXeon D-1649n FirmwareAll versions
IntelXeon D-1653n FirmwareAll versions
IntelXeon D-1702 FirmwareAll versions
IntelXeon D-1712tr FirmwareAll versions
IntelXeon D-1713nt FirmwareAll versions
IntelXeon D-1713nte FirmwareAll versions
IntelXeon D-1714 FirmwareAll versions
IntelXeon D-1715ter FirmwareAll versions
IntelXeon D-1718t FirmwareAll versions
IntelXeon D-1722ne FirmwareAll versions
IntelXeon D-1726 FirmwareAll versions
IntelXeon D-1732te FirmwareAll versions
IntelXeon D-1733nt FirmwareAll versions
IntelXeon D-1734nt FirmwareAll versions
IntelXeon D-1735tr FirmwareAll versions
IntelXeon D-1736 FirmwareAll versions
IntelXeon D-1736nt FirmwareAll versions
IntelXeon D-1739 FirmwareAll versions

Showing 50 of 209 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2022-26343?
Improper access control in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
How severe is CVE-2022-26343?
CVE-2022-26343 has a CVSS score of 6.7/10 (MEDIUM severity). The EPSS model estimates a 0.25% probability of exploitation in the next 30 days.
How do I fix CVE-2022-26343?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-26343?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST