Improper authentication in the software installer for the Intel(R) NUC HDMI Firmware Update Tool for NUC7i3DN, NUC7i5DN, NUC7i7DN before version 1.78.1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
References
Link | Resource |
---|---|
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00568.html | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
History
19 Nov 2021, 13:05
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : 4.6
v3 : 7.8 |
CWE | CWE-287 | |
References | (MISC) https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00568.html - Patch, Vendor Advisory | |
CPE | cpe:2.3:o:intel:nuc7i5dn_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:intel:nuc7i3dn_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:intel:nuc7i7dn_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:intel:nuc7i7dn:-:*:*:*:*:*:*:* cpe:2.3:h:intel:nuc7i3dn:-:*:*:*:*:*:*:* cpe:2.3:h:intel:nuc7i5dn:-:*:*:*:*:*:*:* |
17 Nov 2021, 19:24
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-11-17 19:15
Updated : 2024-02-04 22:08
NVD link : CVE-2021-0096
Mitre link : CVE-2021-0096
CVE.ORG link : CVE-2021-0096
JSON object : View
Products Affected
intel
- nuc7i5dn
- nuc7i3dn
- nuc7i5dn_firmware
- nuc7i3dn_firmware
- nuc7i7dn
- nuc7i7dn_firmware
CWE
CWE-287
Improper Authentication