CVE-2022-38787

HIGHCVSS 7.8/10EPSS 0.18%

Last modified

CVE-2022-38787 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Improper input validation in firmware for some Intel(R) FPGA products before version 2.7.0 Hotfix may allow an authenticated user to potentially enable escalation of privilege via local access.. EPSS estimates a 0.18% chance of exploitation in the next 30 days.

Description

Improper input validation in firmware for some Intel(R) FPGA products before version 2.7.0 Hotfix may allow an authenticated user to potentially enable escalation of privilege via local access.

Metrics

CVSS 3.1
7.8/10

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.18%

8.2th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
IntelAgilex 7 Fpga F-Series 019 Firmware<= 2.7.0
IntelAgilex 7 Fpga F-Series 023 Firmware<= 2.7.0
IntelAgilex 7 Fpga F-Series 006 Firmware<= 2.7.0
IntelAgilex 7 Fpga F-Series 008 Firmware<= 2.7.0
IntelAgilex 7 Fpga F-Series 027 Firmware<= 2.7.0
IntelAgilex 7 Fpga F-Series 014 Firmware<= 2.7.0
IntelAgilex 7 Fpga F-Series 012 Firmware<= 2.7.0
IntelAgilex 7 Fpga F-Series 022 Firmware<= 2.7.0
IntelAgilex 7 Fpga I-Series 022 Firmware<= 2.7.0
IntelAgilex 7 Fpga I-Series 041 Firmware<= 2.7.0
IntelAgilex 7 Fpga I-Series 035 Firmware<= 2.7.0
IntelAgilex 7 Fpga I-Series 027 Firmware<= 2.7.0
IntelAgilex 7 Fpga I-Series 019 Firmware<= 2.7.0
IntelAgilex 7 Fpga I-Series 040 Firmware<= 2.7.0
IntelAgilex 7 Fpga I-Series 023 Firmware<= 2.7.0
IntelAgilex 7 Fpga M-Series 039 Firmware<= 2.7.0
IntelStratix 10 Nx 2100 Fpga Firmware<= 2.7.0
IntelStratix 10 Dx 2800 Fpga Firmware<= 2.7.0
IntelStratix 10 Dx 2100 Fpga Firmware<= 2.7.0
IntelStratix 10 Dx 1100 Fpga Firmware<= 2.7.0
IntelStratix 10 Tx 1650 Fpga Firmware<= 2.7.0
IntelStratix 10 Tx 2500 Fpga Firmware<= 2.7.0
IntelStratix 10 Tx 2100 Fpga Firmware<= 2.7.0
IntelStratix 10 Tx 850 Fpga Firmware<= 2.7.0
IntelStratix 10 Tx 400 Fpga Firmware<= 2.7.0
IntelStratix 10 Tx 1100 Fpga Firmware<= 2.7.0
IntelStratix 10 Tx 2800 Fpga Firmware<= 2.7.0
IntelStratix 10 Sx 650 Fpga Firmware<= 2.7.0
IntelStratix 10 Sx 400 Fpga Firmware<= 2.7.0
IntelStratix 10 Sx 1100 Fpga Firmware<= 2.7.0
IntelStratix 10 Sx 850 Fpga Firmware<= 2.7.0
IntelStratix 10 Sx 1650 Fpga Firmware<= 2.7.0
IntelStratix 10 Sx 2100 Fpga Firmware<= 2.7.0
IntelStratix 10 Sx 2500 Fpga Firmware<= 2.7.0
IntelStratix 10 Sx 2800 Fpga Firmware<= 2.7.0
IntelStratix 10 Mx 2100 Fpga Firmware<= 2.7.0
IntelStratix 10 Mx 1650 Fpga Firmware<= 2.7.0
IntelStratix 10 Gx 2110 Fpga Firmware<= 2.7.0
IntelStratix 10 Gx 1660 Fpga Firmware<= 2.7.0
IntelStratix 10 Gx 650 Fpga Firmware<= 2.7.0
IntelStratix 10 Gx 400 Fpga Firmware<= 2.7.0
IntelStratix 10 Gx 850 Fpga Firmware<= 2.7.0
IntelStratix 10 Gx 2100 Fpga Firmware<= 2.7.0
IntelStratix 10 Gx 1100 Fpga Firmware<= 2.7.0
IntelStratix 10 Gx 2500 Fpga Firmware<= 2.7.0
IntelStratix 10 Gx 10m Fpga Firmware<= 2.7.0
IntelStratix 10 Gx 2800 Fpga Firmware<= 2.7.0
IntelStratix 10 Gx 1650 Fpga Firmware<= 2.7.0

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2022-38787?
Improper input validation in firmware for some Intel(R) FPGA products before version 2.7.0 Hotfix may allow an authenticated user to potentially enable escalation of privilege via local access.
How severe is CVE-2022-38787?
CVE-2022-38787 has a CVSS score of 7.8/10 (HIGH severity). The EPSS model estimates a 0.18% probability of exploitation in the next 30 days.
How do I fix CVE-2022-38787?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-38787?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST