CVE-2022-32231

MEDIUMCVSS 6.7/10EPSS 0.21%

Last modified

CVE-2022-32231 is a medium-severity vulnerability rated 6.7/10 on the CVSS scale. Improper initialization in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.. EPSS estimates a 0.21% chance of exploitation in the next 30 days.

Description

Improper initialization in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

Metrics

CVSS 3.1
6.7/10

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.21%

11.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
IntelXeon Gold 6138p FirmwareAll versions
IntelXeon Bronze 3104 FirmwareAll versions
IntelXeon Bronze 3106 FirmwareAll versions
IntelXeon Gold 5115 FirmwareAll versions
IntelXeon Gold 5118 FirmwareAll versions
IntelXeon Gold 5119t FirmwareAll versions
IntelXeon Gold 5120 FirmwareAll versions
IntelXeon Gold 5120t FirmwareAll versions
IntelXeon Gold 5122 FirmwareAll versions
IntelXeon Gold 6126 FirmwareAll versions
IntelXeon Gold 6126f FirmwareAll versions
IntelXeon Gold 6126t FirmwareAll versions
IntelXeon Gold 6128 FirmwareAll versions
IntelXeon Gold 6130 FirmwareAll versions
IntelXeon Gold 6130f FirmwareAll versions
IntelXeon Gold 6130t FirmwareAll versions
IntelXeon Gold 6132 FirmwareAll versions
IntelXeon Gold 6134 FirmwareAll versions
IntelXeon Gold 6136 FirmwareAll versions
IntelXeon Gold 6138 FirmwareAll versions
IntelXeon Gold 6138f FirmwareAll versions
IntelXeon Gold 6138t FirmwareAll versions
IntelXeon Gold 6140 FirmwareAll versions
IntelXeon Gold 6142 FirmwareAll versions
IntelXeon Gold 6142f FirmwareAll versions
IntelXeon Gold 6144 FirmwareAll versions
IntelXeon Gold 6146 FirmwareAll versions
IntelXeon Gold 6148 FirmwareAll versions
IntelXeon Gold 6148f FirmwareAll versions
IntelXeon Gold 6150 FirmwareAll versions
IntelXeon Gold 6152 FirmwareAll versions
IntelXeon Gold 6154 FirmwareAll versions
IntelXeon Platinum 8153 FirmwareAll versions
IntelXeon Platinum 8156 FirmwareAll versions
IntelXeon Platinum 8158 FirmwareAll versions
IntelXeon Platinum 8160 FirmwareAll versions
IntelXeon Platinum 8160f FirmwareAll versions
IntelXeon Platinum 8160t FirmwareAll versions
IntelXeon Platinum 8164 FirmwareAll versions
IntelXeon Platinum 8168 FirmwareAll versions
IntelXeon Platinum 8170 FirmwareAll versions
IntelXeon Platinum 8176 FirmwareAll versions
IntelXeon Platinum 8176f FirmwareAll versions
IntelXeon Platinum 8180 FirmwareAll versions
IntelXeon Silver 4108 FirmwareAll versions
IntelXeon Silver 4109t FirmwareAll versions
IntelXeon Silver 4110 FirmwareAll versions
IntelXeon Silver 4112 FirmwareAll versions
IntelXeon Silver 4114 FirmwareAll versions
IntelXeon Silver 4114t FirmwareAll versions

Showing 50 of 181 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2022-32231?
Improper initialization in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
How severe is CVE-2022-32231?
CVE-2022-32231 has a CVSS score of 6.7/10 (MEDIUM severity). The EPSS model estimates a 0.21% probability of exploitation in the next 30 days.
How do I fix CVE-2022-32231?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-32231?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST