CVE-2023-28722 is a high-severity vulnerability affecting specific Intel NUC BIOS firmware versions prior to IN0048, including models like the NUC 8 Mainstream-G Kit NUC8i5INH and NUC8i7INH. This flaw, stemming from improper buffer restrictions, could allow a privileged local attacker to achieve escalation of privilege. With a CVSS score of 7.8, it presents a significant risk, requiring local access but having low attack complexity and potentially leading to high impact on confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
inwhl357.0049CPE matchmatch criteria | cpe:2.3:o:intel:nuc_8_mainstream-g_kit_nuc8i5inh_firmware:inwhl357.0049:*:*:*:*:*:*:* | ||
inwhl357.0049CPE matchmatch criteria | cpe:2.3:o:intel:nuc_8_mainstream-g_kit_nuc8i7inh_firmware:inwhl357.0049:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.