CVE-2022-37343

MEDIUMCVSS 6.7/10EPSS 0.16%

Last modified

CVE-2022-37343 is a medium-severity vulnerability rated 6.7/10 on the CVSS scale. Improper access control in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.. EPSS estimates a 0.16% chance of exploitation in the next 30 days.

Description

Improper access control in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

Metrics

CVSS 3.1
6.7/10

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.16%

5.2th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
IntelAtom C3338r FirmwareAll versions
IntelAtom C3436l FirmwareAll versions
IntelAtom C3558r FirmwareAll versions
IntelAtom C3758r FirmwareAll versions
IntelAtom C3336 FirmwareAll versions
IntelAtom C3308 FirmwareAll versions
IntelAtom C3508 FirmwareAll versions
IntelAtom C3538 FirmwareAll versions
IntelAtom C3558 FirmwareAll versions
IntelAtom C3708 FirmwareAll versions
IntelAtom C3750 FirmwareAll versions
IntelAtom C3758 FirmwareAll versions
IntelAtom C3808 FirmwareAll versions
IntelAtom C3830 FirmwareAll versions
IntelAtom C3850 FirmwareAll versions
IntelAtom C3858 FirmwareAll versions
IntelAtom C3950 FirmwareAll versions
IntelAtom C3955 FirmwareAll versions
IntelAtom C3958 FirmwareAll versions
IntelAtom C3338 FirmwareAll versions
IntelAtom P5731 FirmwareAll versions
IntelAtom P5362 FirmwareAll versions
IntelAtom P5352 FirmwareAll versions
IntelAtom P5342 FirmwareAll versions
IntelAtom P5332 FirmwareAll versions
IntelAtom P5322 FirmwareAll versions
IntelAtom P5742 FirmwareAll versions
IntelAtom P5721 FirmwareAll versions
IntelAtom P5752 FirmwareAll versions
IntelAtom P5931b FirmwareAll versions
IntelAtom P5962b FirmwareAll versions
IntelXeon D-2745nx FirmwareAll versions
IntelXeon D-2757nx FirmwareAll versions
IntelXeon D-2777nx FirmwareAll versions
IntelXeon D-2798nx FirmwareAll versions
IntelXeon D-1702 FirmwareAll versions
IntelXeon D-1712tr FirmwareAll versions
IntelXeon D-1713nt FirmwareAll versions
IntelXeon D-1713nte FirmwareAll versions
IntelXeon D-1714 FirmwareAll versions
IntelXeon D-1715ter FirmwareAll versions
IntelXeon D-1718t FirmwareAll versions
IntelXeon D-1722ne FirmwareAll versions
IntelXeon D-1726 FirmwareAll versions
IntelXeon D-1732te FirmwareAll versions
IntelXeon D-1733nt FirmwareAll versions
IntelXeon D-1734nt FirmwareAll versions
IntelXeon D-1735tr FirmwareAll versions
IntelXeon D-1736 FirmwareAll versions
IntelXeon D-1736nt FirmwareAll versions

Showing 50 of 114 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2022-37343?
Improper access control in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
How severe is CVE-2022-37343?
CVE-2022-37343 has a CVSS score of 6.7/10 (MEDIUM severity). The EPSS model estimates a 0.16% probability of exploitation in the next 30 days.
How do I fix CVE-2022-37343?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-37343?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST