CVE-2022-0004 is a medium-severity vulnerability affecting certain Intel Processors, where hardware debug modes and processor INIT settings can override security locks within Intel Boot Guard and Intel TXT. This flaw allows an unauthenticated attacker with physical access to potentially achieve escalation of privilege. The CVSS score is 6.8, indicating high impact on confidentiality, integrity, and availability, but requiring physical access for exploitation. There is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed on CISA's KEV catalog, suggesting no active exploitation. While community discussion and media coverage are present, its EPSS score is very low, indicating a minimal probability of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 16.0.15CPE matchmatch criteria | cpe:2.3:o:intel:core_i3-12100_firmware:*:*:*:*:*:*:*:* | ||
< 16.0.15CPE matchmatch criteria | cpe:2.3:o:intel:core_i3-12100f_firmware:*:*:*:*:*:*:*:* | ||
< 16.0.15CPE matchmatch criteria | cpe:2.3:o:intel:core_i3-12100t_firmware:*:*:*:*:*:*:*:* | ||
< 16.0.15CPE matchmatch criteria | cpe:2.3:o:intel:core_i3-12300t_firmware:*:*:*:*:*:*:*:* | ||
< 16.0.15CPE matchmatch criteria | cpe:2.3:o:intel:core_i3-12300_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.