CVE-2022-21933

A

SUS VivoMini/Mini PC device has an improper input validation vulnerability. A local attacker with system privilege can use system management interrupt (SMI) to modify memory, resulting in arbitrary code execution for controlling the system or disrupting service.

Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:asus:vc65-c1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asus:vc65-c1:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:asus:pb60v_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asus:pb60v:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:asus:pb60g_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asus:pb60g:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:asus:pb60s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asus:pb60s:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:asus:pa90_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asus:pa90:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:asus:pb50_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asus:pb50:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:asus:pb60_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asus:pb60:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:asus:pb61v_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asus:pb61v:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:asus:ts10_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asus:ts10:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:asus:pn40_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asus:pn40:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:asus:pn60_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asus:pn60:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:asus:pn30_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asus:pn30:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:asus:un65u_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asus:un65u:-:*:*:*:*:*:*:*

History

21 Nov 2024, 06:45

Type Values Removed Values Added
CVSS v2 : 7.2
v3 : 7.8
v2 : 7.2
v3 : 6.7
References () https://www.twcert.org.tw/tw/cp-132-5547-34bc4-1.html - Third Party Advisory () https://www.twcert.org.tw/tw/cp-132-5547-34bc4-1.html - Third Party Advisory

Information

Published : 2022-01-21 09:15

Updated : 2024-11-21 06:45


NVD link : CVE-2022-21933

Mitre link : CVE-2022-21933

CVE.ORG link : CVE-2022-21933


JSON object : View

CWE
CWE-20

Improper Input Validation

CWE-787

Out-of-bounds Write