Xeon D 2738 Firmware
Vendor:
First CVE: May 12, 2022 · Active for 4 years
16
Total CVEs
More Total CVEs than 93% of tracked products
8.0
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
6.2
Avg CVSS
Higher Avg CVSS than 28% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Xeon D 2738 Firmware over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 12, 2022
4 years ago
Most Recent CVE
Nov 14, 2023
987 days ago
CVE Severity & Scoring
Xeon D 2738 Firmware16 CVEs
81%
19%
All CVEs353,240 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local15 (93.8%)
Network0 (0.0%)
Unknown0 (0.0%)
Physical1 (6.3%)
Adjacent Network0 (0.0%)
Attack Complexity
Low16 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None16 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low7 (43.8%)
High8 (50.0%)
None1 (6.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-23583HIGH Sequence of processor instructions leads to unexpected behavior for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege and/or in | Nov 14, 2023 | 7.8 | 27 | NO | NO |
CVE-2021-0154HIGH Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access. | May 12, 2022 | 7.8 | 26 | NO | NO |
CVE-2021-33123HIGH Improper access control in the BIOS authenticated code module for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local acce | May 12, 2022 | 7.8 | 24 | NO | NO |
CVE-2022-33196MEDIUM Incorrect default permissions in some memory controller configurations for some Intel(R) Xeon(R) Processors when using Intel(R) Software Guard Extensions which may allow a privileg | Feb 16, 2023 | 6.7 | 22 | NO | NO |
CVE-2022-26343MEDIUM Improper access control in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. | Feb 16, 2023 | 6.7 | 22 | NO | NO |
CVE-2021-33124MEDIUM Out-of-bounds write in the BIOS authenticated code module for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access. | May 12, 2022 | 6.7 | 22 | NO | NO |
CVE-2022-26373MEDIUM Non-transparent sharing of return predictor targets between contexts in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local | Aug 18, 2022 | 5.5 | 21 | NO | NO |
CVE-2022-21233MEDIUM Improper isolation of shared resources in some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access. | Aug 18, 2022 | 5.5 | 21 | NO | NO |
CVE-2022-0004MEDIUM Hardware debug modes and processor INIT setting that allow override of locks for some Intel(R) Processors in Intel(R) Boot Guard and Intel(R) TXT may allow an unauthenticated user | May 12, 2022 | 6.8 | 21 | NO | NO |
CVE-2022-38087MEDIUM Exposure of resource to wrong sphere in BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access. | May 10, 2023 | 5.5 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (16 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (16 CVEs).
Media Mentions
Signals from CVEs in this product scope (16 CVEs).
Top CNAs Publishing CVEs For Xeon D 2738 Firmware
Top CWEs
Versions
No cataloged versions.